1.4.1

    Kubernetes

    Develop, deploy and debug Kubernetes applications

    Rank#539
    Publisher ms-kubernetes-toolsRegistry openvsx1,162,568Last scanned Sep 8, 2026, 08:11 AMRegistryHomepageGitHub
    Created
    9 years ago
    Last commit
    last week
    Latest release
    1.4.12 months ago

    Security Findings

    6

    Dynamic exec of remote content (VSX)

    SuspiciousScanner

    Fetched content reaches a dynamic exec sink in tools/save-swagger-enums.js: fetch(

    tools/save-swagger-enums.js

    Hardcoded secrets/API keys

    SuspiciousScanner

    Secret Keyword: ****

    dist/797.extension.js

    Hardcoded secrets/API keys

    SuspiciousScanner

    Secret Keyword: use s...****

    dist/extension.js

    Sensitive file access

    SuspiciousScanner

    Access to sensitive file: ~/.kube

    Owner name resembles a known brand

    MaliciousLineage

    'vscode-kubernetes-tools' contains brand 'kubernetes'

    Transitive delivery to an unrelated extension

    SuspiciousScanner

    Pulls unrelated extension(s) via extensionPack/Dependencies (payload lives in the target): redhat.vscode-yaml