Hacker News new | ask | show | jobs
by aborsy 254 days ago
The code base for VSCode seems to be huge. With plug-ins, bloat, all the different things that it does, and large number of installations, it seems an ideal target for vulnerabilities and supply chain attacks.

Anyone knows more the level of risk?