this post was submitted on 14 Mar 2025
18 points (100.0% liked)
VS Code
903 readers
5 users here now
founded 2 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
This feels way too apologetic by MS to me. Dunno if that's mainly the reporting in this article.
They "accidentally included" stuff that didn't belong in there. They obfuscated their code. Multiple red flags were hit.
For me, moving fast in blocking spread seems warranted. Maybe it shouldn't trigger removal on installs immediately, depending on how fast they can check.
The authors ban circumvention and outdated dependency the cause but not an issue claims were dubious at best as well.
Sure, maybe no ill intent. But that doesn't mean security practices should not happen.