Bloom Security’s Extension Resurrection research exposes a blind spot in developer security

Wait 5 sec.

Security teams have spent years scrutinizing software dependencies, package repositories and build pipelines. Bloom Security‘s latest research suggests that another part of the software supply chain deserves closer attention: the extensions developers install inside their IDEs. The company’s “Extension Resurrection” research examined extension packs on the Visual Studio Code Marketplace and Open VSX. Bloom found […]This story continues at The Next Web