Signal
VS Code introduces two-hour delay on extension updates to mitigate supply chain risks
Evidence first: scan the strongest sources, then decide whether to go deeper.
Published 2026-06-08 06:08 UTCUpdated 2026-06-08 17:20 UTC
rss
security_toolingsupply_chainsoftware_updates
Trend in the last 24h
Source links open
Source links and full evidence are open here. Archive history, compare-over-time, alerts, exports, API, integrations, and workflow are paid.
No card needed for the free brief.
Evidence trail (top sources)
top sources (2 domains)domains are deduped. counts indicate coverage, not truth.2 top sources shown
limited source diversity in top sources
Overview
Microsoft has implemented a two-hour delay for automatic updates of Visual Studio Code extensions starting with version 1.123. This measure aims to reduce the risk of supply chain attacks by allowing a buffer period after an extension is published before it is auto-updated.
Entities
MicrosoftVisual Studio Code
Score total
0.97
Momentum 24h
2
Posts
2
Origins
2
Source types
1
Duplicate ratio
0%
Why now
- Supply chain threats are increasingly exploited by attackers targeting development tools.
- Recent incidents have highlighted the need for proactive defenses in software update mechanisms.
- Microsoft's update aligns with industry trends to improve software supply chain security.
Why it matters
- Supply chain attacks on software extensions can compromise developer environments and downstream applications.
- Delaying automatic updates allows time to detect and mitigate malicious or faulty extension releases.
- This security measure enhances trust in the VS Code ecosystem, widely used by developers globally.
LLM analysis
Topic mix: lowPromo risk: lowSource quality: medium
Recurring claims
- VS Code applies a two-hour delay before automatically updating extensions to mitigate supply chain attacks
How sources frame it
- Microsoft: neutral
All evidence
All evidence
VS Code adds 2-hour delay for extension updates to combat supply chain threats
SC Media · scworld.com · 2026-06-08 17:20 UTC
VS Code Adds 2-Hour Extension Auto-Update Delay to Limit Supply Chain Attacks
thehackernews · thehackernews.com · 2026-06-08 06:08 UTC
Show filters & breakdown
Posts loaded: 0Publishers: 2Origin domains: 2Duplicates: -
Showing 2 / 0
Top publishers (this list)
- SC Media (1)
- thehackernews (1)
Top origin domains (this list)
- scworld.com (1)
- thehackernews.com (1)