VS Code Marketplace Verified

Go

by Go Team at Google · 19.8M users · 4.3 rating
e48bc7f6-8ed5-56c7-80f9-a67d12e1e731 | v0.57.2
44/ 100
MEDIUM risk
No change since v0.57.0
Analyst verdict
Review before use

The AI review rates the findings as likely false positive, but the risk score (44/100) still counts them.

Analysis record

Analysed
1 months ago
Version
v0.57.2
Artifact
SHA256 F72…5D4
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

14 detail rows

Publisher Evidence

Low

Go Team at Google

Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.

83
Noisy-finding weight
x1.00
Publisher domain
go.dev
Observed
Store verification signal
Verified publisher
Verified
Extension portfolio
2
Portfolio

12 evidence rows available.

Finding Categories

1
Network

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality strong.

This is the official Go language extension for Visual Studio Code, published by the "golang" developer account with over 18 million users. The extension's stated purpose is providing "Rich Go language support" including language server features, debugging, and code intelligence—capabilities that legitimately require filesystem access and process execution.

The filesystem and process access patterns are fully justified by the extension's purpose. The dependency findings in /tmp/extract-b206452378968a879cbe1d396d3bd3fe0254d3311fefd3f5c6ceafcc69014d65-3809919923/extension/package.json list standard VS Code extension packages: [email protected], [email protected], [email protected], and [email protected]. These are official Microsoft packages required for language server protocol implementation and debugger integration. Additional dependencies like [email protected], [email protected], and [email protected] are common utility packages used for file pattern matching, version comparison, and HTTP requests—standard operations for any language tooling extension.

The single network finding, NET-WEBSOCKET-extension/dist/debugAdapter.js-13576, represents a websocket connection in the debug adapter. This is expected behavior for a debugger extension. The Go debugger must communicate with the debug adapter protocol server to provide breakpoints, variable inspection, and step-through debugging. The websocket call originates from extension/dist/debugAdapter.js, which is the compiled debug adapter binary—a normal component of any VS Code debugger extension.

No credential-access findings target actual secrets. The findings summary shows zero secret-related detections, zero credential-access patterns, and zero findings related to .env files, SSH keys, cloud credentials, or VS Code secret storage. The extension does not request or access any sensitive configuration files beyond what is necessary for Go tooling.

The strongest counterargument to this verdict would be the presence of any network communication or bundled code in the dist/ directory. However, the websocket finding in debugAdapter.js is documented debugger behavior, not exfiltration. Bundled JavaScript in dist/ directories is standard build output from webpack or similar tools, not intentional obfuscation. With zero malware signatures, zero IoC matches, zero obfuscation findings, and zero code-smell detections, there is no evidence of malicious intent.

This extension represents the baseline for legitimate IDE tooling: a language server that reads source files to provide IntelliSense, spawns Go compiler processes for compilation, and communicates with debug adapters for debugging. All findings align with expected behavior for this class of extension.

Key Reasons

  • Official extension from verified golang publisher with 18M+ users
  • Zero malware signatures or IoC findings
  • All dependencies are standard VS Code language server packages
  • Network finding is expected debugger websocket communication
  • No credential access or secret-related findings

False Positive Considerations

  • Dependency scanning on standard VS Code packages
  • Network finding from legitimate debugger websocket communication
  • Bundled dist/ files containing standard build output

Reviewed 2026-05-23; recommended action: no action; model confidence 92%.

VS Code version history

Risk trend by version

4 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
44
Change since first
No change
Change from previous
No change
Versions:
First analyzed version
0.53.1
Apr 5, 2026
Risk range
44 to 44
Across analyzed versions
Latest analyzed version
0.57.2
Aug 22, 2026
Selected version
medium
Version
v0.57.2
1 months ago
Risk score
44
Findings
14
Change vs previous
No change

Pick any point on the chart to explore that version's code below.

About This Extension

Rich Go language support for Visual Studio Code

Frequently Asked Questions