Rank#428
Publisher googlecloudtoolsRegistry openvsx817,773Last scanned Sep 14, 2026, 12:43 PMRegistryHomepageGitHub
- Created
- 13 years ago
- Last commit
- 7 days ago
- Latest release
- v15.31.0last week
Security Findings
6Dynamic exec of remote content (VSX)
SuspiciousScannerDownload-and-execute in package.json: curl -fsSL https://code-server.dev/install.sh | sh
package.json
Hardcoded secrets/API keys3×
SuspiciousScannerPrivate Key: BEGIN...****
Secret Keyword: ****
Secret Keyword: array...****
dist/extension.js
Sensitive file access
SuspiciousScannerAccess to sensitive file: homedir(),".cache","firebase","logs","vsce-debug.log");e.length>0&&S.existsSync(E.join(e[0],"firebase.json"))&&(t=E.join...
Transitive delivery to an unrelated extension
SuspiciousScannerPulls unrelated extension(s) via extensionPack/Dependencies (payload lives in the target): graphql.vscode-graphql-syntax