
Product
Introducing Socket Scanning for VS Code Marketplace Extensions
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.
@htekdev/azure-devops-extension-sdk
Advanced tools
Client SDK for developing Azure DevOps extensions.
The client SDK enables web extensions to communicate to the host frame. It can be used to:
A full API reference of can be found here.
See the Develop a web extension for Azure DevOps documentation for instructions on getting started with a new extension. You can also refer to the azure-devops-extension-sample repository as a working reference.
azure-devops-extension-sdk to the list of dependencies in your package.jsonimport * as SDK from "azure-devops-extension-sdk" to your TypeScript codeWhen you have rendered your extension content, call SDK.init(). Your extension content will not be displayed until you have notified the host frame that you are ready. There are two options for doing this:
SDK.init() with no loaded optionSDK.init({ loaded: false }) to start initializing the SDK. Then call SDK.notifyLoadSucceeded() once you have finished your initial rendering. This allows you to make other SDK calls while your content is still loading (and hidden behind a spinner).Example:
import * as SDK from "azure-devops-extension-sdk";
SDK.init();
A full API reference of can be found here.
This project has adopted the Microsoft Open Source Code of Conduct. For more information see the Code of Conduct FAQ or contact opencode@microsoft.com with any additional questions or comments.
FAQs
Azure DevOps web extension JavaScript library.
The npm package @htekdev/azure-devops-extension-sdk receives a total of 4 weekly downloads. As such, @htekdev/azure-devops-extension-sdk popularity was classified as not popular.
We found that @htekdev/azure-devops-extension-sdk demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.

Research
/Security News
Socket uncovered two malicious VS Code themes in a GlassWorm-linked cluster with thousands of installs across VS Code Marketplace and Open VSX.

Security News
/Company News
Capital One is partnering with Socket to proactively secure its open source supply chain.