3 comments

  • speakingmoistly 6 hours ago

    The better place to flag this would probably be on their issue tracker. The release on the marketplace being five hours ago, it's not unlikely that GH releases are manual and lagging behind (seeing plenty of this in projects that publish container images, the updated image comes through Renovate hours before anything shows up on release pages).

    • warhorse10_9 5 hours ago

      Thanks, I followed their security.md to contact them. Appreciate the insight on a possible standard lack of synchronous versions.

      • speakingmoistly an hour ago

        > Appreciate the insight on a possible standard lack of synchronous versions.

        Looking closer at the commit and release history, it looks like poor release hygiene, really. Commits hint at a 0.44.0 release that doesn't show up in tags and the changelog file that is included with the source (in the extension that you pull down and the repository) isn't readily maintained.

        The absence of a verifiable link between the marketplace artifacts and the underlying code should probably give people pause about the trustworthiness of the extension. I bet a good chunk of what's on that marketplace is in that situation.