<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0">
  <channel>
    <title>InfoQ - Visual Studio Code - News</title>
    <link>https://www.infoq.com</link>
    <description>InfoQ Visual Studio Code News feed</description>
    <item>
      <title>VS Code 1.123 Adds Two-Hour Extension Update Delay to Limit Supply Chain Attacks</title>
      <link>https://www.infoq.com/news/2026/06/vscode-extension-update-delay/?utm_campaign=infoq_content&amp;utm_source=infoq&amp;utm_medium=feed&amp;utm_term=Visual+Studio+Code-news</link>
      <description>&lt;img src="https://www.infoq.com/styles/static/images/logo/logo_bigger.jpg"/&gt;&lt;p&gt;VS Code 1.123 adds a two-hour delay before auto-updating extensions to newly published versions, creating a revocation window against supply chain attacks. The delay does not apply to trusted publishers like Microsoft, GitHub, and OpenAI. Similar cooldown mechanisms have now spread across pip, RubyGems, npm, pnpm, Yarn, and Bun.&lt;/p&gt; &lt;i&gt;By Steef-Jan Wiggers&lt;/i&gt;</description>
      <category>Visual Studio Code</category>
      <category>Application Security</category>
      <category>Software Supply Chain</category>
      <category>Development</category>
      <category>Architecture &amp; Design</category>
      <category>DevOps</category>
      <category>news</category>
      <pubDate>Thu, 18 Jun 2026 10:15:00 GMT</pubDate>
      <guid>https://www.infoq.com/news/2026/06/vscode-extension-update-delay/?utm_campaign=infoq_content&amp;utm_source=infoq&amp;utm_medium=feed&amp;utm_term=Visual+Studio+Code-news</guid>
      <dc:creator>Steef-Jan Wiggers</dc:creator>
      <dc:date>2026-06-18T10:15:00Z</dc:date>
      <dc:identifier>/news/2026/06/vscode-extension-update-delay/en</dc:identifier>
    </item>
  </channel>
</rss>
