|
Available on the Visual Studio Code Marketplace for Visual Studio Code |
Available on the OpenVSX registry for Cursor, VSCodium, Windsurf, Theia & friends |
|---|---|
|
|
|
This repository is the public issue tracker for the Meterian VS Code extension that detects and helps you fix open‑source vulnerabilities directly in your IDE. You can download it from the marketplace: it's completely free to use.
Alternatively, if you are using an alternative IDE (i.e. Cursor) you can find it on the open-vsx marketplace.
Super easy to use:
- Install from your chosen marketplace (once!)
- Open a project (if not open yet)
- An analysis starts automatically, if the project is supported :)
- See the report, drill down into the details if you want
- Use autofix to automatically resolve the issues!
Use this repo to:
- Report bugs (with logs, repro steps, and environment details)
- Request features and improvements
- Ask usage questions
⚠️ Security disclosures
Please do not file security vulnerabilities here. Email security@meterian.io with details and a way to reproduce. We’ll acknowledge within 2 business days.
- Search open issues to avoid duplicates.
- Include:
- Extension version (e.g.,
v1.2.3) & VS Code version (e.g.,1.93.0) - OS (e.g., macOS 14.5 / Windows 11 / Ubuntu 22.04)
- Project language & package manager (e.g., Java + Maven/Gradle, JavaScript + npm/yarn/pnpm, Python + pip/poetry, etc.)
- Reproduction steps and expected vs. actual behavior
- Logs from VS Code:
Help → Toggle Developer Tools → Console - Screenshots, if relevant
- Extension version (e.g.,
Remember: security issues are not tracked here; use security@meterian.io.
- Discord (community support):
- Documentation: Visit the documentation website
- FAQ: See our FAQ document
The system is powered by the Meterian Kiwi vulnerability database. The APIs are called passing an opaque identifier as an authorization header; the data transferred is the name, version and language of a library. Additionally another API is called from Meterian Heidi backend services, which is used to track activity. Any identity information is anonymized, encrypted with strong cypher, and cannot be decyphered.
While the extension is closed source and this repository contains no code, your feedback here directly shapes our backlog and priorities. The extension is completely free to use.