Only the latest release gets security fixes. Each release ships at the same version to both the Visual Studio Marketplace and Open VSX, so upgrading on either registry gets you the fix.
Do not open a public issue for a security problem. Use GitHub's private vulnerability reporting instead: open the repository's Security tab, then choose Report a vulnerability. You get a response within a few days.
- RepoDock makes no network requests and collects no telemetry. It stores only folder paths and last-opened timestamps, in VS Code's local storage.
- The only external process it runs is
git status --porcelain=v2 --branch, throughexecFilewith no shell, against repositories under the folders the user configured. - The published bundle has no runtime npm dependencies.
- In Restricted Mode, which VS Code applies to an untrusted workspace, it ignores
repodock.directoriesandrepodock.excludewhen those settings come from workspace configuration. A checked-out repository therefore cannot redirect scanning.