Analyzing cross-langage dependencies in VSCode Ecosystem
Title: Analyzing cross-langage dependencies in VSCode Ecosystem
DNr: NAISS 2025/22-433
Project Type: NAISS Small Compute
Principal Investigator: Mohannad Alhanahnah <mohannad.alhanahnah@chalmers.se>
Affiliation: Chalmers tekniska högskola
Duration: 2025-05-01 – 2026-05-01
Classification: 10205
Keywords:

Abstract

This project aims to understand characteristics of direct and transitive dependencies in the VSCode ecosystem and understand the security vulnerabilities of these dependencies. We use static analysis to transitively identify dependencies of VSCode extensions. Then we will identify potential vulnerabilities that these dependencies impose.