Eclipse Foundation Implements Pre-Publish Security Checks for Open VSX Extensions
Summary
Hide ▲
Show ▼
The Eclipse Foundation is introducing mandatory pre-publish security checks for extensions submitted to the Open VSX Registry. This shift from a reactive to a proactive approach aims to prevent malicious extensions from being published and to combat supply chain threats. The new checks will flag impersonation, exposed credentials, and known malicious patterns, with enforcement beginning in March 2026 after a February 2026 trial period. The move follows increasing attacks on open-source package registries and extension marketplaces, including recent incidents of compromised publisher accounts and poisoned updates.
Timeline
-
04.02.2026 08:26 1 articles · 16h ago
Eclipse Foundation to Enforce Pre-Publish Security Checks for Open VSX Extensions
The Eclipse Foundation will enforce pre-publish security checks for extensions submitted to the Open VSX Registry, starting in March 2026. The checks will flag impersonation, exposed credentials, and known malicious patterns, with a trial period in February 2026 to fine-tune the system and reduce false positives. This move aims to prevent malicious extensions from being published and to combat supply chain threats.
Show sources
- Eclipse Foundation Mandates Pre-Publish Security Checks for Open VSX Extensions — thehackernews.com — 04.02.2026 08:26
Information Snippets
-
The Eclipse Foundation will enforce pre-publish security checks for Open VSX Registry extensions to combat supply chain threats.
First reported: 04.02.2026 08:261 source, 1 articleShow sources
- Eclipse Foundation Mandates Pre-Publish Security Checks for Open VSX Extensions — thehackernews.com — 04.02.2026 08:26
-
Pre-publish checks will flag impersonation, exposed credentials, and known malicious patterns.
First reported: 04.02.2026 08:261 source, 1 articleShow sources
- Eclipse Foundation Mandates Pre-Publish Security Checks for Open VSX Extensions — thehackernews.com — 04.02.2026 08:26
-
The enforcement will begin in March 2026 after a trial period in February 2026.
First reported: 04.02.2026 08:261 source, 1 articleShow sources
- Eclipse Foundation Mandates Pre-Publish Security Checks for Open VSX Extensions — thehackernews.com — 04.02.2026 08:26
-
Microsoft's Visual Studio Marketplace already has a similar multi-step vetting process in place.
First reported: 04.02.2026 08:261 source, 1 articleShow sources
- Eclipse Foundation Mandates Pre-Publish Security Checks for Open VSX Extensions — thehackernews.com — 04.02.2026 08:26