Issue #147  (Extension Publisher Trust)02/12/25

Advertisement
HubSpot's Starter Bundle for Startups

Unlock the potential of your growing startup with HubSpot's Starter Customer Platform.

HubSpot Starter Bundle
For a discounted price of just $20/month, unlock access to the Starter edition of HubSpot’s six core products for marketing, sales, and customer service – powered by HubSpot’s Smart CRM – all for the price of one. Built for startups like yours, HubSpot Starter has all the essential tools you need to scale.

There's been a lot of talk lately about security in VS Code, some of which I've shared in this newsletter. Microsoft is, of course, continuing to take steps to make VS Code more secure and if nothing else to notify you when you might be doing something risky.

As you'll see in the links below, the January update for VS Code is now out. One of the changes is an interesting one for installing extensions. It's loosely referred to as extension publisher trust. After updating to the latest version of VS Code, you'll see this when you try to install an extension.
 
Extension Publisher Trust in VS Code

As the screenshot above demonstrates, there's a new dialog box that appears when you try to install a new extension from a publisher that you haven't installed from before. The dialog will also warn you if the publisher is not verified.

If you install an extension pack or an extension with dependencies, your 'trust' for that publisher will also apply to the other extensions in the pack. If you want to manage publisher trust on a per-publisher basis, you can run the Extensions: Manage Trusted Extensions Publishers command in your command palette.
 
Editing Extension Publisher Trust in VS Code

From there you'll get a list of all publishers that you have 'trusted'. And note that as soon as the new version of VS Code with this feature is installed, it will implicitly 'trust' all your existing extension's publishers. This 'trust' also applies to publishers that you currently don't have any extensions from but that you've previously installed extensions for under this version of VS Code.

If you install an extension via the command line, this does not add the extension's publisher to your trusted list.

Now on to this week's hand-picked links!
 

VS Code Tools

ReactToolkit — A VS Code extension that provides a curated list of resources for React devs, including the official documentation, popular libraries, tools, and more – all accessible from a convenient sidebar.

todo comments for Linear — The missing link between VS Code and Linear (product planning/building tool), to create, track, link and reference tasks right from your code comments without context switching.

Meco — Free your newsletters from the inbox. Move your newsletters to a space built for reading and declutter your inbox in seconds.   Sponsor 

Material Icon Theme — A popular icon set for VS Code, which includes file and folder icons, with instructions on how to customize the colors, folder themes, icon opacity, etc.


VS Code Theme of the Week

Rosé Pine — Described as "all natural pine, faux fur and a bit of soho vibes for the classy minimalist." As the name implies, the colors have a light pink-ish hue.

Rosé Pine Theme for VS Code

The extension includes three primary versions of the theme, along with no-italics versions of each, so six variations in all. The one shown above is the main theme, while the other two are light theme and a more traditional looking dark theme.
 

VS Code Articles & Videos

VS Code 1.97 (January 2025 Updates) — The latest updates to VS Code, which cover December and January, including Copilot edit predictions, repositioning the command palette, extension publisher trust (see intro above), and lots more.

Enter Flow State with Auto-edit — This is a feature recently added to the Cody VS Code extension, which I've linked to before. This helps you go "beyond autocomplete to suggest context-aware edits natively in VS Code."

Brain Food, Delivered Daily — Every day Refind analyzes thousands of articles and sends you only the best, tailored to your interests. Loved by 527,190 curious minds.   Sponsor 

📺 Fix Broken Comments in VS Code — I've never experienced the problem demonstrated in this YouTube short, but it might be good to know the solution if it's something you've run into.

Best of the Rest

SWE-Kit — A headless IDE with AI-native tools for building custom coding agents with any agentic framework and LLMs of your choice.

Kompad — A beautiful, customizable note-taking app that allows you to create, edit, and synchronize your technical documents.

Tech Productivity — A free weekly newsletter for tech professionals who want to get stuff done. Tools, app, articles, and tips on productivity, work culture, brain science, wellness, and more.   Sponsor 

tiny-glimmer.nvim — A tiny Neovim plugin that adds subtle animations to various operations (requires Neovim >= 0.10).

Suggestions?

If you have any link suggestions, including a tool, article, or other resource related to VS Code or another IDE, you can hit reply, send it via DM on X, or via chat on Bluesky.

That's it for this issue.

Happy VS Coding!
Louis
VSCode.Email
@LouisLazaris
Copyright © VSCode.Email. All rights reserved.

Not affiliated with Microsoft, Visual Studio Code, or any of its trademarks.