Policy result for this exact artifact
Exact artifact intelligence
Pylance
ms-python.vscode-pylance@2026.2.109Security outcomeReview needed
The extension exposes sensitive capabilities or non-confirmed risk evidence that needs context.
100% analysis coverage · exact version onlyms-pythonvs-marketplaceArtifact
f23f205ad5e17ebdReview decision-relevant behavior before installation.
Review the grouped evidence, affected locations, and whether each behavior matches the extension’s purpose.
55/100Review needed
Diagnostic risk index for this exact artifact — not a probability of malice.
100
Required analyzers completed
0
Diagnostic index, not probability
7 contextual groups kept separate
Power describes access, not intent
4 behavior groups need context before approval.
Native binary dist/bundled/bin/win32-arm64/pylance-service.exe has no companion checksum or signature file and no documented provenance.
f23f205ad5e17ebd5c050eef7970e8ec1e764b81939c43835a7f98b781fb72e2Build 9a51c780c109 · ruleset 2026.07.19
Evidence that drives review
Native binary dist/bundled/bin/win32-arm64/pylance-service.exe has no companion checksum or signature file and no documented provenance.
2 observed locations · review evidence
YARA rule ide_scanner_embedded_pe matched dist/bundled/bin/win32-x64/pylance-service.exe.
1 observed location · review evidence
Extension contains 2 native artifacts (e.g. dist/bundled/bin/win32-arm64/pylance-service.exe).
1 observed location · review evidence