Adding Prettier (https://marketplace.visualstudio.com/items?itemName=esbenp.p...) for its underdiscussed Markdown formatting keeps READMEs and blog posts clean as well.
Adding Prettier (https://marketplace.visualstudio.com/items?itemName=esbenp.p...) for its underdiscussed Markdown formatting keeps READMEs and blog posts clean as well.
The extension functionality does look great though. I wrote some similar functions in my nvim which I would have really a hard time living without.
I'm not a VSCode user myself, but it's pretty much the same story with nvim.
edit: I suppose what I'm really getting at, is that, depending on what their security measures look like, the VSCode extension store might be giving some false sense of security.
I suppose I could mention that on a Mac, I use Objective-See’s tools to watch what programs do in the background. And also on a Mac, you have to grant access to apps first otherwise they can’t normally access files. Of course, that breaks down in reality as most apps are useless if they can’t access files.
If you really want a scare, consider that if you compromise an ecosystem package (e.g. npm), you can run on developer machines, CI systems and possibly in production, while if you compromise a VS Code extension, you only get dev machines.
If you’re looking for a bit of extra protection, you can run VS Code from a virtual machine or even run it from Docker. Though the usual docker approach, using remote containers extension, still runs on your local computer. There’s GitHub Codespaces or Google Cloud Shell that can run VS Code remotely in a VM, though.
Just sprinkling bits of awareness around by bringing some of these considerations up whenever I can. It's an uphill battle, although, the general carelessness around extension and dependency use I'm seeing - and that even after all the shit that's been going on in that space - makes it one worth to fight.
Edit: Regarding the chain of trust you mention, that one has sort of come and gone, and there is not a whole lot of trust involved in the processes I'm saddled up with.
Programs should run as their own users. Programs should be granted access to files opened via system (desktop environment) file picker APIs or when passed in via a shell. Desktop environments & shells would need to be modified to allow this, of course.
> Programs should be granted access to files opened via system (desktop environment) file picker APIs or when passed in via a shell.
For example, this would render the file tree of any IDE or advanced editor (like VS code) completely useless. I can count on one hand the number of times I've used the system file picker when programming.
Not sure if I consider vim either simple or sane, but then again, it was first released quite a while ago, in 1991 for the Amiga, and it was based on the even older original vi from 1971 - the era of physical TTYs, no mice, and punchcard programming (ugh! glad I wasn't born yet).
Can hardly blame grandpa for forgetting and acting strange every once in a while at his age :)
When grandpa refuses to wear glasses even though he can't see jack then it's time to take his car's key off of his hands.
0: https://marketplace.visualstudio.com/items?itemName=telesoho...
https://marketplace.visualstudio.com/items?itemName=dendron....