Uploaded image for project: 'Red Hat OpenShift Dev Spaces (formerly CodeReady Workspaces) '
  1. Red Hat OpenShift Dev Spaces (formerly CodeReady Workspaces)
  2. CRW-8313

Provide the ability to disable "Install from VSIX..." functionality in VS Code IDE

XMLWordPrintable

    • False
    • Hide

      None

      Show
      None
    • False
    • Release Notes
    • Hide
      = Disable "Install from VSIX..." feature in Visual Studio Code - Open Source ("Code - OSS")

      Previously, users were able to manually download and install unapproved Visual Studio Code extensions in the `.vsix` format. This could lead to the installation of potentially malicious extensions.

      With this release, admins can use ConfigMap to disable the *Install from VSIX...* feature and prevent the download and installation of unapproved extensions.
      Show
      = Disable "Install from VSIX..." feature in Visual Studio Code - Open Source ("Code - OSS") Previously, users were able to manually download and install unapproved Visual Studio Code extensions in the `.vsix` format. This could lead to the installation of potentially malicious extensions. With this release, admins can use ConfigMap to disable the *Install from VSIX...* feature and prevent the download and installation of unapproved extensions.
    • Enhancement
    • Done

      Currently, users can manually download unapproved extensions in VSIX format from the Microsoft Marketplace or OpenVSX. They can then manually install these extensions in a Dev Spaces workspace, bypassing the need to install from an internal extension registry, which contains a curated list of extensions.

      The ability to do the above circumvents security and allows users to install potentially malicious extensions.

       

              rnikiten Roman Nikitenko
              mbenitez@redhat.com Martha Benitez
              Anatolii Bazko Anatolii Bazko
              Jana Vrbkova Jana Vrbkova
              Votes:
              1 Vote for this issue
              Watchers:
              15 Start watching this issue

                Created:
                Updated:
                Resolved: