logoalt Hacker News

echoangletoday at 9:10 AM4 repliesview on HN

You get asked if you trust the folder you’re opening every single time you open a new folder in VsCode. Everyone probably always just says yes but it’s not like it doesn’t tell you that opening untrusted folders is dangerous.


Replies

mjdvtoday at 9:33 AM

Until this post it wasn't clear to me that just opening and trusting a directory can cause code to be run without taking any other explicit actions that seem like they might involve running code, like running tests. My bad, but still!

show 4 replies
duskdozertoday at 10:17 AM

The message isn't very clear on what exactly is allowed to happen. Just intuitively, I wouldn't have expected simply opening a folder would "automatically execute tasks" because that's strange to me

show 1 reply
windowpainstoday at 1:15 PM

I’ve always defaulted to no.

srousseytoday at 9:12 AM

This is when I say no.

Then copy-paste my default .dev-container directory and reload.