← Back to context

Comment by fc417fc802

4 months ago

Vim is hardly secure either. Extensions in both provide for arbitrary code execution.

No doubt, but I (and I suspect many others) rarely update plugins and I have a very select list of plugins that I use (mostly from one guy), and I just use git to manage them. I never see churn, but that might just be me.

I assume you could probably do the same with VSCode, but I suspect there's a cultural difference that pushes you to always update? Do things stop working because of churn?