Attackers can abuse VS Code configuration files for RCE when a GitHub Codespaces user opens a repository or pull request.
Eclipse Foundation to require pre-publish security checks for Open VSX extensions to reduce VS Code supply-chain risk.
Cybersecurity researchers from Socket’s Threat Research team have identified a developer-compromise supply chain attack ...
VS Code's official Snap package on Linux has a bug first reported in 2024 that still hasn't been fixed and is gobbling up storage space.