By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
World of SoftwareWorld of SoftwareWorld of Software
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Search
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
Reading: Eclipse Foundation Mandates Pre-Publish Security Checks for Open VSX Extensions
Share
Sign In
Notification Show More
Font ResizerAa
World of SoftwareWorld of Software
Font ResizerAa
  • Software
  • Mobile
  • Computing
  • Gadget
  • Gaming
  • Videos
Search
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Have an existing account? Sign In
Follow US
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
World of Software > Computing > Eclipse Foundation Mandates Pre-Publish Security Checks for Open VSX Extensions
Computing

Eclipse Foundation Mandates Pre-Publish Security Checks for Open VSX Extensions

News Room
Last updated: 2026/02/04 at 2:15 AM
News Room Published 4 February 2026
Share
Eclipse Foundation Mandates Pre-Publish Security Checks for Open VSX Extensions
SHARE

Ravie LakshmananFeb 04, 2026Supply Chain Security / Secure Coding

The Eclipse Foundation, which maintains the Open VSX Registry, has announced plans to enforce security checks before Microsoft Visual Studio Code (VS Code) extensions are published to the open-source repository to combat supply chain threats.

The move marks a shift from a reactive to a proactive approach to ensure that malicious extensions don’t end up getting published on the Open VSX Registry.

“Up to now, the Open VSX Registry has relied primarily on post-publication response and investigation. When a bad extension is reported, we investigate and remove it,” Christopher Guindon, director of software development at the Eclipse Foundation, said.

“While this approach remains relevant and necessary, it does not scale as publication volume increases and threat models evolve.”

The change comes as open-source package registries and extension marketplaces have increasingly become attack magnets, enabling bad actors to target developers at scale through a variety of methods such as namespace impersonation and typosquatting. As recently as last week, Socket flagged an incident where a compromised publisher’s account was used to push poisoned updates.

By implementing pre-publish checks, the idea is to limit the window of exposure and flag the following scenarios, as well as quarantine suspicious uploads for review instead of publishing them immediately –

  • Clear cases of extension name or namespace impersonation
  • Accidentally published credentials or secrets
  • Known malicious patterns

It’s worth noting that Microsoft already has a similar multi-step vetting process in place for its Visual Studio Marketplace. This includes scanning incoming packages for malware, then rescanning every newly published package “shortly” after it’s been published, and periodic bulk rescanning of all the packages.

The extension verification program is expected to be rolled out in a staged fashion, with the maintainers using the month of February 2026 to monitor newly published extensions without blocking publication to fine-tune the system, reduce false positives, and improve feedback. The enforcement will begin next month.

“The goal and intent are to raise the security floor, help publishers catch issues early, and keep the experience predictable and fair for good-faith publishers,” Guindon said.

“Pre-publish checks reduce the likelihood that obviously malicious or unsafe extensions make it into the ecosystem, which increases confidence in the Open VSX Registry as shared infrastructure.”

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Print
Share
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article Epic Movie Night Deal: Save 0 Off This Samsung 65-Inch 4K TV Epic Movie Night Deal: Save $100 Off This Samsung 65-Inch 4K TV
Next Article Mozilla Adds Option to Disable New AI Features Coming to Firefox Browser Mozilla Adds Option to Disable New AI Features Coming to Firefox Browser
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow

Latest News

Microsoft Warns Python Infostealers Target macOS via Fake Ads and Installers
Microsoft Warns Python Infostealers Target macOS via Fake Ads and Installers
Computing
Astro Announces Version 6 Beta with Redesigned Development Server and First-Class Cloudflare Workers
Astro Announces Version 6 Beta with Redesigned Development Server and First-Class Cloudflare Workers
News
X’s Paris HQ raided by French cybercrime officers over Grok chatbot –  News
X’s Paris HQ raided by French cybercrime officers over Grok chatbot – News
News
Starbucks sells majority stake in China business to Boyu Capital in US billion deal · TechNode
Starbucks sells majority stake in China business to Boyu Capital in US$4 billion deal · TechNode
Computing

You Might also Like

Microsoft Warns Python Infostealers Target macOS via Fake Ads and Installers
Computing

Microsoft Warns Python Infostealers Target macOS via Fake Ads and Installers

3 Min Read
Starbucks sells majority stake in China business to Boyu Capital in US billion deal · TechNode
Computing

Starbucks sells majority stake in China business to Boyu Capital in US$4 billion deal · TechNode

1 Min Read
China becomes first country to ban hidden car door handles · TechNode
Computing

China becomes first country to ban hidden car door handles · TechNode

4 Min Read
CWG profit jumps 84% in 2025 as software sales surge
Computing

CWG profit jumps 84% in 2025 as software sales surge

4 Min Read
//

World of Software is your one-stop website for the latest tech news and updates, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Topics

  • Computing
  • Software
  • Press Release
  • Trending

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

World of SoftwareWorld of Software
Follow US
Copyright © All Rights Reserved. World of Software.
Welcome Back!

Sign in to your account

Lost your password?