#1 Mention risks with Market Place supply chain attacks?

开启中
dfr2 年之前创建 · 0 条评论

When users are enabled with arbitrary code install they must be warned about the consequences of installing extensions without first reviewing them, especially if the extensions involves connecting with SSH to the clusters.

See this article for a general description of the risks associated with the Market Place and this one for a quantitative analysis.

When users are enabled with arbitrary code install they must be warned about the consequences of installing extensions without first reviewing them, especially if the extensions involves connecting with SSH to the clusters. See [this article](https://www.developer-tech.com/news/2023/jan/09/visual-studio-marketplace-supply-chain-attack-vector/) for a general description of the risks associated with the Market Place and [this one](https://blog.checkpoint.com/securing-the-cloud/malicious-vscode-extensions-with-more-than-45k-downloads-steal-pii-and-enable-backdoors/) for a quantitative analysis.
登录 并参与到对话中。
未选择标签
未选择里程碑
未指派成员
1 名参与者
正在加载...
取消
保存
这个人很懒,什么都没留下。