Is Microsoft ever going to implement proper VS Code plugin sandboxing? There are so many good extensions I would like to use, but I hate the security implications of loading yet more unvetted code for a nice-to-have.
Then again, I see that the top buzz in the industry is about Claws and letting LLMs run loose with only a handshake agreement to be safe, and I already know the answer.
The only real answer is something like web assembly and that would be a major breaking change for them.
This is why allot run dev containers but agreed this really should be top priority but instead is probably in the "maybe if we have a major security incident" bucket of concerns as these things often are
There's no malware in it currently, but I understand your concerns - I could be lying, go rogue later, or just get my access stolen.
One option is to vet a version yourself and disable auto-update, but that's not really feasible to spend time on for most people.
Sorry, no sleight intended against you, just a general concern as more and more cool utilities keep getting built into the platform.
No offense taken, you actually made me reconsider trying out random extensions that sound like mine to make sure i'm not reinventing the wheel
Doesn't seem like it. It will be stuck in a security theater situation, just like Chrome extensions. Not an upgrade from the old highly powerful firefox extensions or those of the Atom text editor.
[dead]