Signal

VS Code introduces two-hour delay on extension updates to mitigate supply chain risks

Evidence first: scan the strongest sources, then decide whether to go deeper.

Published 2026-06-08 06:08 UTCUpdated 2026-06-08 17:20 UTC
rss
security_toolingsupply_chainsoftware_updates
Trend in the last 24h
Source links open
Source links and full evidence are open here. Archive history, compare-over-time, alerts, exports, API, integrations, and workflow are paid.
No card needed for the free brief.
Evidence trail (top sources)
top sources (2 domains)domains are deduped. counts indicate coverage, not truth.
2 top sources shown
limited source diversity in top sources
Overview

Microsoft has implemented a two-hour delay for automatic updates of Visual Studio Code extensions starting with version 1.123. This measure aims to reduce the risk of supply chain attacks by allowing a buffer period after an extension is published before it is auto-updated.

Entities
MicrosoftVisual Studio Code
Score total
0.97
Momentum 24h
2
Posts
2
Origins
2
Source types
1
Duplicate ratio
0%
Why now
  • Supply chain threats are increasingly exploited by attackers targeting development tools.
  • Recent incidents have highlighted the need for proactive defenses in software update mechanisms.
  • Microsoft's update aligns with industry trends to improve software supply chain security.
Why it matters
  • Supply chain attacks on software extensions can compromise developer environments and downstream applications.
  • Delaying automatic updates allows time to detect and mitigate malicious or faulty extension releases.
  • This security measure enhances trust in the VS Code ecosystem, widely used by developers globally.
LLM analysis
Topic mix: lowPromo risk: lowSource quality: medium
Recurring claims
  • VS Code applies a two-hour delay before automatically updating extensions to mitigate supply chain attacks
How sources frame it
  • Microsoft: neutral
All evidence
All evidence
VS Code Adds 2-Hour Extension Auto-Update Delay to Limit Supply Chain Attacks
thehackernews · thehackernews.com · 2026-06-08 06:08 UTC
Show filters & breakdown
Posts loaded: 0Publishers: 2Origin domains: 2Duplicates: -
Showing 2 / 0
Top publishers (this list)
  • SC Media (1)
  • thehackernews (1)
Top origin domains (this list)
  • scworld.com (1)
  • thehackernews.com (1)