Skip to content

Minimum release age setting for extensions #272765

@HendrikJan

Description

@HendrikJan

I could not find any existing issues requesting this functionality

To decrease the risk of malicious extensions (like the recent GlassWorm attack), it would be great to have a setting that enforces a minimum extension age.
Package managers like pnpm introduced this same functionality recently: pnpm/pnpm#9921

With this setting:

  • extensions need to be at least x days old before they appear in the extensions.
  • automatic updates of extensions happen only x days after they are released.

This way, there is a longer time in which malicious extensions can be detected before the become widespread.

This setting should probably be set to a couple of days by default.

Metadata

Metadata

Labels

extensionsIssues concerning extensionsfeature-requestRequest for new features or functionality

Type

No type

Projects

No projects

Relationships

None yet

Development

No branches or pull requests

Issue actions