Skip to content

Only allow package names for plugin names #42712

Closed
@DanielRosenwasser

Description

@DanielRosenwasser

We will need to only allow package names for loaded editor plugin names, to mitigate issues described in https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-1639

We'll be porting this to the following TypeScript versions:

  • 3.1.7
  • 3.7.6
  • 3.9.8
  • 4.0.6
  • 4.1.4
  • 4.2+

Metadata

Metadata

Assignees

No one assigned

    Labels

    BugA bug in TypeScriptFix AvailableA PR has been opened for this issue

    Type

    No type

    Projects

    No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions