Skip to content

Use identifiable prefixes in issued tokens to improve security and tooling support #1338

@mbarbero

Description

@mbarbero

To improve the efficiency of secret scanners and reduce false positives, Open VSX should adopt identifiable prefixes for issued tokens.

For example, PAT could be issued with a prefix like ovsxp_.

This change would have several benefits:

  • Improved security tooling support: secret scanners can more easily identify valid Open VSX tokens and differentiate them from random strings.
  • Reduced false positives: currently, scanners may mistakenly flag arbitrary strings as potential secrets. A clear prefix format would reduce this noise.
  • Consistency with industry practices: platforms like GitHub have already adopted this approach (see their explanation).

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions