Hacker News new | ask | show | jobs
by warhorse10_9 62 days ago
Thanks, I followed their security.md to contact them. Appreciate the insight on a possible standard lack of synchronous versions.
1 comments

> Appreciate the insight on a possible standard lack of synchronous versions.

Looking closer at the commit and release history, it looks like poor release hygiene, really. Commits hint at a 0.44.0 release that doesn't show up in tags and the changelog file that is included with the source (in the extension that you pull down and the repository) isn't readily maintained.

The absence of a verifiable link between the marketplace artifacts and the underlying code should probably give people pause about the trustworthiness of the extension. I bet a good chunk of what's on that marketplace is in that situation.