Skip to content

Quote *.vsix glob in release-vscode.yml #45

Description

@pedrofuentes

Sentinel finding (SNT-2025-0722-002, Yellow #1)

release-vscode.yml:42 uses unquoted *.vsix glob in the Open VSX publish command. If multiple .vsix files exist (stale artifacts, build debris), all would be published. Quote the glob or use an explicit filename.

Also consider quoting secret variables on lines 39 and 42 as defensive best practice.

Metadata

Metadata

Assignees

No one assigned

    Labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions