EclipseFdn / EclipseFdn/publish-extensions
Why is TypeScript native preview extension marked as malicious?
- Dominant language
- JavaScript
- Stars
- 342
- Forks
- 428
- Avg merge
- 40m
- Merged PRs (30d)
- 2
Description
https://marketplace.visualstudio.com/items?itemName=TypeScriptTeam.native-preview was recently marked as malicious.
Looks like it changed in https://github.com/EclipseFdn/publish-extensions/commit/f59bf949edf047998436e4ef1b1ee97d215f1b7c, but I can't see any reason why it was flagged.
Contributor guide
Research direction
Start by reviewing commit f59bf949edf047998436e4ef1b1ee97d215f1b7c and the TypeScript native preview extension entry on the VS Code Marketplace. Compare the change with the repository's malicious-extension handling and determine whether the flag is expected; done means documenting the reason or identifying a concrete correction.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- javascript, typescript, vscode
- Domain
- security, tooling
- Issue type
- Bug
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Activity status
- Quiet
- Clarity
- Needs clarification
- Newbie friendliness
- 45/100