SocketDev / SocketDev/socket-vscode

Vs Code Extension

Open
#58 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

question
Dominant language
TypeScript
Stars
30
Forks
14
PR merge metrics
No merged PRs in 30d

Description

Following the recent Axios incident, I noticed Socket highlighted on the npm website and decided to take a look. I was about to install the VS Code extension, however VS Code warns that the extension’s publisher is not verified.
Given that this is a security‑focused tool, this is a concerning first impression. Without publisher or domain verification, it’s difficult to establish confidence that the extension is genuinely published and maintained by Socket.
Could you clarify why the publisher domain is not verified, and whether there are plans to complete this verification? Once verified, I’d be much more comfortable evaluating and potentially adopting the extension.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start with the VS Code Marketplace listing and the publisher or domain verification details referenced in the report. Done means explaining why the publisher is unverified and either completing verification or documenting a concrete plan for it.

Written by the indexing model from the issue text.

Assessment

Tech stack
typescript, vscode
Domain
devtools, security
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Quiet
Clarity
Needs clarification
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.