VS Code extensions are less secure than browser extensions or even NPM packages

Related Stories

Trusting your own judgement on 'AI' is a risk

Avoiding generative models is the rational and responsible thing to do

Loading Native Postgres Extensions

OxCaml - a set of extensions to the OCaml programming language.

React-like Hooks Using Vanilla JavaScript in Less Than 50 Lines of Code

Claude Code vs Windsurf — am I missing something? Or is windsurf just better?

You need much less memory than time

Study shows that hope may be even more essential to well-being than happiness or gratitude

Anyway to write polars with less code ??

Waymo rides cost more than Uber or Lyft and people are paying anyway

Show HN: VS Code extension to share code snippets instantly

Folders Inside Packages

Meta buys a nuclear power plant (more or less)

NPM Is Down

Websites are tracking you via browser fingerprinting

Soon Your Orange Juice Will Have Even Less Real Orange in It

Browser Game: guess my AI's password + source code

Are we the sexbots? Tech vs. consent

Pnpm and Npm difference

AI Weather Model Is More Accurate, Less Expensive Than Traditional Forecasting

Scientists Show Reforestation Helps Cool the Planet Even More Than Thought

Is QA even QA anymore? Or just post-dev clerical work?

Humpback Whales Are Way Cooler Than You

A modest proposal: Packages that need to build C code should do so with `-w` (disable all warnings)

What more Zig has to offer than C++ or D?

iFixit says the Switch 2 is even harder to repair than the original

I used AI-powered calorie counting apps, and they were even worse than expected

The number of ads on Amazon Prime Video has doubled in less than 18 months

How I fixed error wrapping blocks making the code harder to read for the first time in VS Code

New VS Code Extension: Auto-load remote files from URL placeholders (via symlinks)