Skip to content

Evaluate alternatives to @vscode/vsce-sign #1831

@spoenemann

Description

@spoenemann

The ovsx package depends on @vscode/vsce-sign through the usage of @vscode/vsce. The vsce-sign has a problematic license, see https://gitlab.eclipse.org/eclipsefdn/emo-team/iplab/-/issues/25926

We should evaluate whether the vsce-sign package can be replaced, e.g. with https://github.com/filiptronicek/node-ovsx-sign

Metadata

Metadata

Assignees

No one assigned

    Labels

    cli(Component: cli) Open VSX command-line clientsecurityVulnerabilities or improvements to harden security and protect user data

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions