VS Code Extension Policies Existed for 18 Months — GitHub Didn’t Use Them. Will Your Clients?
Posted in

VS Code Extension Policies Existed for 18 Months — GitHub Didn’t Use Them. Will Your Clients?

VS Code’s AllowedExtensions policy shipped in November 2024. GitHub — a Microsoft subsidiary — wasn’t enforcing it when a poisoned Nx Console extension walked out with 3,800 internal repos in 11 minutes. The policy framework was never missing. The enforcement was. Here’s the Intune remediation script and the Copilot/MCP guardrails that close the exact attack path TeamPCP used.

Join the GitHub Copilot Global Bootcamp: Master AI Coding Tools with Workshops Worldwide and Open Source Chat Extension
Posted in

Join the GitHub Copilot Global Bootcamp: Master AI Coding Tools with Workshops Worldwide and Open Source Chat Extension

Join the new GitHub Copilot Global Bootcamp from June 17 to July 10, featuring virtual and … Join the GitHub Copilot Global Bootcamp: Master AI Coding Tools with Workshops Worldwide and Open Source Chat ExtensionRead more