The announcement follows the significant momentum and continued growth of the Open VSX Registry, which recently surpassed 300 million monthly downloads and has become a critical infrastructure for AI-native IDEs, cloud development environments, and VS Code-compatible platforms used by millions of developers worldwide.
“Open VSX is critical infrastructure for modern development platforms, making it an increasingly attractive target for malicious actors and reinforcing the need for proactive risk mitigation,” said Mike Milinkovich, executive director of the Eclipse Foundation. “As adoption accelerates and the threat landscape becomes more sophisticated, responsible security research is essential. This program creates a clear pathway for researchers to collaborate with us and be recognized for protecting the ecosystem.”.
Strengthening supply chain security through responsible disclosure
As extension registries play an increasingly central role in modern software development, they have also become part of the active threat landscape of the software supply chain. Attackers have demonstrated their ability to exploit extension ecosystems to distribute malicious code, compromise development environments, and access sensitive data.
The Open VSX Registry has introduced a number of proactive security measures to address these risks, including pre-publication verification, malicious pattern detection, and infrastructure improvements to increase resilience and trust.
The Security Researchers Recognition Program builds upon these efforts by:
Promoting the early and responsible disclosure of vulnerabilities
Providing a direct and transparent notification process
Support for corrective action coordinated with maintenance providers and stakeholders
Strengthening collaboration with the global security research community
Publicly recognize high-impact contributions
A recognition-based model to support the security research community
The Open VSX Security Researcher Recognition Program is designed to complement existing security practices by focusing on recognition, transparency, and collaboration, rather than financial incentives.
Eligible contributors may receive:
Public recognition in the Open VSX Security Hall of Fame
Shareable digital badges and certificates of recognition
Promotional rewards based on impact and contribution level
The award is based on the impact of the finding, the quality of the report, and adherence to responsible disclosure practices. The program is open to independent researchers, academic institutions, security consultancies, open-source contributors, and developers who identify real-world risks in the Open VSX ecosystem.
Support for an open and trusted development infrastructure
Open VSX is a vendor-independent extension registry, managed by the Eclipse Foundation, that supports a rapidly expanding ecosystem of development tools and platforms. As reliance on extension ecosystems grows, maintaining trust requires both technical security measures and active community participation.
The program reinforces the Eclipse Foundation's overall commitment to advancing:
Software supply chain security
Transparent governance that is independent of suppliers
The long-term sustainability of open source infrastructure
How to participate
Security researchers, developers, and community members are invited to help strengthen the security and trustworthiness of the Open VSX ecosystem. The Open VSX Researcher Recognition Program provides a clear pathway for the responsible disclosure of vulnerabilities, along with opportunities to contribute more broadly to the project and the community.
