Package registries such as npm and PyPI support trusted publishers.
Given recent attacks on package registries, as well as the VSCode marketplace, I believe it would be a good idea for vsce to support this as well.
Also npm added staged publishing today. I believe it’s a good idea for the VSCode marketplace to have this as well.
Package registries such as npm and PyPI support trusted publishers.
Given recent attacks on package registries, as well as the VSCode marketplace, I believe it would be a good idea for vsce to support this as well.
Also npm added staged publishing today. I believe it’s a good idea for the VSCode marketplace to have this as well.