Skip to content

Data quality issue with VSCode Extension Unique Identifiers (hyperlinks in https://osv.dev/vulnerability/ ... ) #4505

@devex-luis

Description

@devex-luis

Example: https://osv.dev/vulnerability/MAL-2025-191167

The reports produced for the VSCode ecosystem does not use the correct unique identifiers for the vscode extensions sourced from the openvsx registry and when you click on the hyperlink as: https://open-vsx.org/SIRILMP.dark-theme-sm (I believe is embedded in the JSON response), you will not be able to view the openvsx marketplace entry for it

VSCode marketplace unique identifier: <publisher.name-of-extension>

OpenVSX marketplace unique identifier: <publisher/name-of-extension>

  • In the openvsx registry, the eclipse foundation uses the concept of a {workspace} for each publisher

Metadata

Metadata

Assignees

No one assigned

    Labels

    data qualityIssues with data quality

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions