Eclipse Foundation Mandates Pre-Publish Security Checks for Open VSX Extensions
ID: 61721b26-5920-5bc3-9cd9-9e4b8fe40145
STIX ID: report--61721b26-5920-5bc3-9cd9-9e4b8fe40145
Feed Name: The Hacker News
The Eclipse Foundation will introduce pre-publish security checks for the Open VSX Registry to proactively block malicious or unsafe VS Code extensions, focusing on issues like namespace impersonation, leaked secrets, and known malicious patterns. Rolled out in stages during February 2026 for monitoring and tuning before enforcement next month, the effort aims to reduce supply chain risk, narrow exposure windows, and align with Microsoft’s vetting approach for the Visual Studio Marketplace.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
