{"id":229758,"date":"2026-06-11T03:30:07","date_gmt":"2026-06-11T07:30:07","guid":{"rendered":"https:\/\/testing.news-you-need.com\/index.php\/2026\/06\/11\/vs-code-adds-2-hour-extension-auto-update-delay-to-limit-supply-chain-attacks\/"},"modified":"2026-06-11T03:30:10","modified_gmt":"2026-06-11T07:30:10","slug":"vs-code-adds-2-hour-extension-auto-update-delay-to-limit-supply-chain-attacks","status":"publish","type":"post","link":"https:\/\/testing.news-you-need.com\/index.php\/2026\/06\/11\/vs-code-adds-2-hour-extension-auto-update-delay-to-limit-supply-chain-attacks\/","title":{"rendered":"VS Code Adds 2-Hour Extension Auto-Update Delay to Limit Supply Chain Attacks"},"content":{"rendered":"<p><a href=\"https:\/\/thehackernews.com\/2026\/06\/vs-code-adds-2-hour-extension-auto.html\">VS Code Adds 2-Hour Extension Auto-Update Delay to Limit Supply Chain Attacks<\/a><\/p>\n<p><a href=\"https:\/\/thehackernews.com\/2026\/06\/vs-code-adds-2-hour-extension-auto.html\">https:\/\/thehackernews.com\/2026\/06\/vs-code-adds-2-hour-extension-auto.html<\/a><\/p>\n<p>Publish Date: <a href=\"publish_date]\">2026-06-08 02:08:00<\/a><\/p>\n<p>Source Domain: <a href=\"thehackernews.com\">thehackernews.com<\/a><\/p>\n<p><strong>Summary:<\/strong><br \/>\nMicrosoft has introduced a two-hour delay for automatic updates of extensions in Visual Studio Code (VS Code) to enhance protection against software supply chain threats. The feature, available in VS Code 1.123, ensures new extensions are updated with a two-hour buffer after publication to provide an additional safety net against potentially compromised or problematic releases. Users can still manually update extensions at any time via the \u201cUpdate\u201d button, and they will see which updates are pending along with reasons and expected automatic update times. This safeguard does not apply to extensions from trusted publishers like Microsoft, GitHub, and OpenAI, which update immediately. This move follows similar recent trends in RubyGems and package managers like Bun, pnpm, npm, and Yarn, where installation delays are implemented to prevent exposure to malicious versions released recently by reducing the time window for them to spread undetected.<\/p>\n<p><strong>Key Points:<\/strong><\/p>\n<ul>\n<li>Microsoft has a two-hour delay for automatic updates of extensions in Visual Studio Code (VS Code) to protect against supply chain threats.<\/li>\n<li>Trusted publishers&#8217; extensions like Microsoft, GitHub, and OpenAI avoid this delay and update immediately.<\/li>\n<li>The change follows similar installation controls in RubyGems and package managers to minimize exposure to new malicious releases.<\/li>\n<li>The features aim to reduce the risk of propagating malware by giving developers time to identify and flag potentially harmful releases.<\/li>\n<\/ul>\n<p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>VS Code Adds 2-Hour Extension Auto-Update Delay to Limit Supply Chain Attacks https:\/\/thehackernews.com\/2026\/06\/vs-code-adds-2-hour-extension-auto.html Publish Date:&#8230;<\/p>\n","protected":false},"author":1,"featured_media":229759,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjPMxcu3ZcBpbZRC5rw9BlnoZMoXgrA-dRRquG6F6PSZZUc0JNzGHbl6c50yqTxs60QyQ5ut5ZC2qP9Csk_mR1Aqi48DO0wwDbUZ6zei45FNO2UgXaU0pOf8gWk8iAT81Ee1XJGrYyFgjYJqCeGTlnYeq-U8Nh4i5cxskA5n3eWyaQqMQPmyMAAR30bDKf2\/s1700-e365\/ms-delay.jpg","fifu_image_alt":"","footnotes":""},"categories":[15],"tags":[32],"class_list":["post-229758","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-malware"],"_links":{"self":[{"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/229758"}],"collection":[{"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/comments?post=229758"}],"version-history":[{"count":1,"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/229758\/revisions"}],"predecessor-version":[{"id":229760,"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/229758\/revisions\/229760"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/media\/229759"}],"wp:attachment":[{"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/media?parent=229758"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/categories?post=229758"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/tags?post=229758"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}