this post was submitted on 01 Mar 2025
24 points (100.0% liked)
VS Code
867 readers
2 users here now
founded 2 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
If the dependency has been compromised then extensions that use that dependency and ship compromised code are also compromised. Its a transitive property if it ships bad code.
With that in mind Microsoft yoinking the extension from the market place and user devices seems reasonable. But what was the "loop" they mention?
From user devices? I for sure, dont want Microsoft to do nothing on my devices. My device, my place, my decision.
The linked issue comment has the info about it
Well that's not ideal.
Thank you :)
Breaking: software with "free" in the name turns out to be malicious