VS Code 1.123 adds a two-hour delay before extensions auto-update to newer versions when automatic updates are enabled.
GitHub confirmed on May 20 that a poisoned VS Code extension installed on an employee’s device gave attackers access to roughly 3,800 internal repositories at the Microsoft-owned code storage and ...