Highlights
- Hardened every agent command entry point so caller-supplied objects resolve back to trusted, user-global configuration.
- Restricted stop and restart actions to sessions owned by the current extension host.
- Corrected the CodeBuddy Code CLI update command.
- Updated
brace-expansion,fast-uri,js-yaml, andundici; the audited dependency tree now reports zero known vulnerabilities. - Refreshed the README, GitHub metadata, brand guidance, security review, and social-preview artwork.
- Added a tag-driven GitHub release workflow that rebuilds and identity-checks the VSIX and publishes a SHA-256 file.
Install the reviewed VSIX
Download vscode-super-cli-1.11.1.vsix below, then run Extensions: Install from VSIX... in VS Code or a compatible editor.
Marketplace and Open VSX publication are separate, owner-controlled operations; this GitHub release is the reviewed source artifact.
Verification
- Extension identity:
mikesoft.vscode-super-cli@1.11.1 - VSIX size: 1,207,751 bytes
- SHA-256:
3641fb4fedb2c4194385b4e909e7de15394e287c93dff2531c474f5ca5d9cfe4 - CI: Windows, macOS, and Linux passed
- CodeQL: passed
- Dependency audit: 0 known vulnerabilities
- Local smoke test: installed successfully with the VS Code CLI in an isolated extensions directory
Full changelog: v1.9.4...v1.11.1