Skip to content

Evaluate alternatives to @vscode/vsce-sign #1831

@spoenemann

Description

@spoenemann

The ovsx package depends on @vscode/vsce-sign through the usage of @vscode/vsce. The vsce-sign has a problematic license, see https://gitlab.eclipse.org/eclipsefdn/emo-team/iplab/-/issues/25926

We should evaluate whether the vsce-sign package can be replaced, e.g. with https://github.com/filiptronicek/node-ovsx-sign

Metadata

Metadata

Assignees

No one assigned

    Labels

    cli(Component: cli) Open VSX command-line clientsecurityVulnerabilities or improvements to harden security and protect user data

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions