More

    Eclipse Foundation — Latest News, Reports & Analysis

    Eclipse Foundation Mandates Pre-Publish Security Checks for Open VSX Extensions

    Eclipse Foundation Mandates Pre-Publish Security Checks for Open VSX Extensions

    Feb 04, 2026
    Supply Chain Security / Secure Coding

    The Eclipse Foundation, which maintains the Open VSX Registry, has announced plans to enforce security checks before Microsoft Visual Studio Code (VS Code) extensions are published to the open-source repository to combat supply chain threats. The move marks a shift from a reactive to a proactive approach to ensure that malicious extensions don’t end up getting published on the Open VSX Registry. “Up to now, the Open VSX Registry has relied primarily on post-publication response and investigation. When a bad extension is reported, we investigate and remove it,” Christopher Guindon, director of software development at the Eclipse Foundation, said . “While this approach remains relevant and necessary, it does not scale as publication volume increases and threat models evolve.” The change comes as open-source package registries and extension marketplaces have increasingly become attack magnets, enabling bad actors to target developers at scale through a variet…

     

    Latest articles

    Related articles