Skip to content

Security Issue: Please allow the very simple delay of the installation of updates by n days #230885

Open
@schittli

Description

@schittli

Type: Bug because of a Security Issue

VS code and plugin updates are in a security-critical context:

  1. on the one hand, you always want / need to install updates as fast as possible in order to close security issues.

  2. on the other hand, there are situations in every project where you must not install updates of the tools used at any price. Because: It could have fatal consequences if a used function suddenly stops working, works different or engineers suddenly invest hours to get the IDE running again with the pipeline.

VS Code currently only offers to install updates “later”. EVERY TIME you restart the IDE, you are asked again to install the updates, because apparently “later” has already been reached.

If you have answered the question about the installation 10 times with “later”, this has the consequence that developers deactivate the automatic updates.

This makes the update logic of VS Code a security risk.

Please allow us to define in how many days we should be asked again when updating.

This solves both problems mentioned at the beginning and provides a professional solution.

Thanks a lot, kind regards,
Thomas

VS Code version: Code 1.93.1 (38c31bc, 2024-09-11T17:20:05.685Z)
OS version: Windows_NT x64 10.0.19045
Modes:

System Info
Item Value
CPUs AMD Ryzen 9 5900X 12-Core Processor (24 x 3693)
GPU Status 2d_canvas: enabled
canvas_oop_rasterization: enabled_on
direct_rendering_display_compositor: disabled_off_ok
gpu_compositing: enabled
multiple_raster_threads: enabled_on
opengl: enabled_on
rasterization: enabled
raw_draw: disabled_off_ok
skia_graphite: disabled_off
video_decode: enabled
video_encode: enabled
vulkan: disabled_off
webgl: enabled
webgl2: enabled
webgpu: enabled
webnn: disabled_off
Load (avg) undefined
Memory (System) 127.91GB (35.72GB free)
Process Argv --crash-reporter-id 856f7e37-1fcf-4a79-b795-cf947af05bd0
Screen Reader no
VM 0%

Metadata

Metadata

Assignees

Labels

install-updateVS Code installation and upgrade system issuesunder-discussionIssue is under discussion for relevance, priority, approach

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions