VS Code Adds 2-Hour Extension Auto-Update Delay to Limit Supply Chain Attacks

Read full story on The Hacker News
Share
VS Code Adds 2-Hour Extension Auto-Update Delay to Limit Supply Chain Attacks
AI disclosure

Summary

Microsoft has announced that Visual Studio Code (VS Code) will apply a two-hour delay before extensions for the integrated development environment (IDE) are updated automatically to a newer version in an attempt to tackle software supply chain threats. "When automatic updates are enabled, new versions are auto-updated two hours after they are published, adding an extra layer of protection

Original reporting

Open original source

Related coverage

Read full article on The Hacker News

Get the AFBytes Brief

Major stories, AI-assisted analysis, and what to watch next. Free, monthly, unsubscribe anytime.