logo

Eclipse Foundation Mandates Pre-Publish Security Checks for Open VSX Extensions

ID: 61721b26-5920-5bc3-9cd9-9e4b8fe40145

STIX ID: report--61721b26-5920-5bc3-9cd9-9e4b8fe40145

Feed Name: The Hacker News

Date Published: 2026-02-04

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

The Eclipse Foundation will introduce pre-publish security checks for the Open VSX Registry to proactively block malicious or unsafe VS Code extensions, focusing on issues like namespace impersonation, leaked secrets, and known malicious patterns. Rolled out in stages during February 2026 for monitoring and tuning before enforcement next month, the effort aims to reduce supply chain risk, narrow exposure windows, and align with Microsoft’s vetting approach for the Visual Studio Marketplace.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.