Skip to content

feat: add vscode extension for threat model editing - #123

Merged
Hacks4Snacks merged 7 commits into
mainfrom
hacks4snacks/vscodeextension
Sep 21, 2026
Merged

Hacks4Snacks merged 7 commits into
mainfrom
hacks4snacks/vscodeextension

Conversation

@Hacks4Snacks

Copy link
Copy Markdown
Owner

Summary

Adds Threat Model Forge Studio to VS Code for editing and analyzing .tm7 and .tmforge.json models directly alongside application code.

Why

Bring diagram authoring, threat analysis, and triage into the developer workflow without requiring a separate application, CLI installation, or analysis service.

Changes

  • Embed the shared Studio canvas, inspectors, stencil catalog, analysis,
    threat triage, comparison, and reporting tools.
  • Bundle the .NET WebAssembly engine in an isolated worker with bounded requests.
  • Integrate VS Code save, dirty state, undo/redo, source editing, and split-view
    synchronization, including rejection of stale edits and analysis results.
  • Add native TM7 saves that preserve unrelated XML, template data, and threats.
    No-op saves retain the original bytes; edited saves may change XML formatting.
  • Cascade element, flow, and page deletion to dependent threats and decisions,
    with undo restoring the original content.
  • Surface analysis findings in Problems on open/save and register JSON schemas
    for manifests, rule packs, and suppressions.
  • Make Studio the default editor for both model formats, replacing read-only previews.
  • Add Marketplace metadata, documentation, file icons, and VSIX packaging.
  • Synchronize extension versions through release-please and generate scoped
    changelogs that exclude plugin-, CLI-, and API-only changes.
  • Attach tested VSIX artifacts and checksums to stable GitHub releases.

Scope

  • Desktop VS Code in trusted workspaces; vscode.dev is not supported.
  • Native line trust boundaries are preserved but not displayed on the canvas.
  • Full restart recovery and remote-host execution were not separately tested.
  • Marketplace publication remains manual; this PR does not publish the extension.

Comment thread src/ThreatModelForge.Studio/src/vscode.tsx Fixed
};
try
{
using (XmlReader probe = XmlReader.Create(stream, settings))
}

stream.Position = 0;
using XmlReader reader = XmlReader.Create(stream, settings);
Comment thread src/ThreatModelForge.Analysis/Tm7ExportPreparer.cs Fixed
Comment thread src/ThreatModelForge.Engine/NativeTm7Document.cs Fixed
Comment thread src/ThreatModelForge.Engine/NativeTm7Document.cs Fixed
@Hacks4Snacks
Hacks4Snacks merged commit 7e83868 into main Sep 21, 2026
11 checks passed
@Hacks4Snacks
Hacks4Snacks deleted the hacks4snacks/vscodeextension branch September 21, 2026 23:06
This was referenced Sep 21, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants