
Security News
GPT-6 Astra Attempts Supply Chain Attacks Against Open Source Maintainers in Testing
GPT-6 Astra hits 100% on ExploitBench and finds zero-days autonomously, while independent tests reveal scope violations and monitoring gaps.
Command line interface for Eclipse Open VSX. Run it via npx or install it with
npm install --global ovsx
ovsx uses open-vsx.org as default instance for publishing and downloading extensions. If you are using a different instance, specify it via the --registryUrl (or -r) argument or an environment variable named OVSX_REGISTRY_URL.
You can use ovsx for publishing VS Code extensions to an Open VSX instance. This is very similar to vsce, the publishing tool for the Visual Studio Code Marketplace.
You must create an Open VSX personal access token before you can use osvx to publish. You can either pass the token via the --pat (or -p) argument, or put it into an environment variable named OVSX_PAT.
Variants:
ovsx publish
packages the extension in the current working directory using vsce and then publishes it.ovsx publish --packagePath <path>
packages the extension in the given path using vsce and then publishes it.ovsx publish <file>
publishes an already packaged file.The publisher field of your extension's package.json defines the namespace into which the extension will be published. Before you publish the first extension in a namespace, you must create it. This requires an access token as described above.
ovsx create-namespace <name>
creates the specifed namespace. The name must correspond to the publisher of your extension.Creating a namespace does not automatically give you the exclusive publishing rights. Initially, everyone will be able to publish an extension with the new namespace. If you want exclusive publishing rights, you can claim ownership of a namespace.
You can use ovsx for downloading extensions from an Open VSX instance. Extensions are identified with the format namespace.extension, and an exact version or version range can be specified with the --versionRange (or -v) argument. The namespace corresponds to the publisher entry of the package.json file.
Variants:
ovsx get <extension>
downloads an extension and saves it to a file as specified in its download URL in the current working directory. This is usually in the format namespace.extension-version.vsix. For target platform specific extensions (e.g. linux-x64) the format is namespace.extension-version@target.vsix.ovsx get <extension> -o <path>
downloads an extension and saves it in the specified file or directory.ovsx get <extension> --metadata
downloads the JSON metadata of an extension and prints it to the standard output.ovsx get <extension> --metadata -o <path>
downloads the JSON metadata of an extension and saves it in the specified file or directory.The login command lets you store an access token for a namespace.
ovsx login <name>
the name must correspond to the publisher of your extension. ovsx will ask you to provide an access token.The logout command lets you remove a stored access token.
ovsx logout <name>
the name must correspond to the publisher of your extension.By default ovsx stores access tokens in the operating system's credential manager (via cross-keychain), falling back to storing them as plaintext in the ~/.ovsx file if the credential manager can't be used. You can also set the environment variable OVSX_STORE=file to force plaintext storage; this is strongly discouraged, as it leaves your tokens readable by anyone with access to your home directory.
FAQs
Command line interface for Eclipse Open VSX
The npm package ovsx receives a total of 63,522 weekly downloads. As such, ovsx popularity was classified as popular.
We found that ovsx demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 5 open source maintainers collaborating on the project.

Security News
GPT-6 Astra hits 100% on ExploitBench and finds zero-days autonomously, while independent tests reveal scope violations and monitoring gaps.

Product
Socket can now send alerts and supply chain attack notifications to Microsoft Teams, with filters that route the right updates to each channel.

Security News
pnpm 12 rewrites the package manager in Rust, cutting install times by up to 90% while preserving pnpm 11 workflows and lockfiles.