You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
A discussion dedicated to the VS Code Web module. Share your thoughts, questions, and feedback here.
Module Scorecard
Presentation & Onboarding
IDE Integration
Credential Hygiene
Restricted-Environment Readiness
Engineering Quality
Overall
17 / 17
25 / 25
N/A
7 / 20
10 / 10
82 / 100
Drilldown
Presentation & Onboarding — 17 / 17
Criterion
Max
Score
Notes
Configuration-mode examples
12
12
README has 6 distinct mode examples: default, custom folder, install extensions, pre-configure settings, pin version via commit_id, and open an existing .code-workspace file — all with sensible defaults shown.
Visual preview
5
5
README embeds , verified to exist (5.3MB gif).
Credential Hygiene — N/A (excluded, 0 pts)
Criterion
Max
Score
Notes
Secrets marked sensitive
16
N/A
Module has no credential/secret inputs — concern does not exist by construction.
Non-hardcoded auth path
4
N/A
Module requires no external auth/API keys; nothing to avoid hardcoding.
Restricted-Environment Readiness — 7 / 20
Criterion
Max
Score
Notes
Mirrorable artifact source
5
0
No variable overrides the download URLs (https://update.code.visualstudio.com/... and https://vscode.download.prss.microsoft.com/...). commit_id only pins a version, install_prefix only changes install location — neither replaces the source URL.
Bring-your-own binary
10
5
use_cached and offline variables let run.sh skip the download entirely if a copy is pre-baked at install_prefix, but neither variable is mentioned anywhere in the README — functionality exists in code only, undocumented.
Egress transparency
3
0
No dedicated network/endpoints section; download hosts only appear in run.sh source, not the README.
Runs without sudo
2
2
run.sh never invokes sudo; all operations (install, extension install, settings merge) run as the agent user.
Engineering Quality — 10 / 10
Criterion
Max
Score
Notes
Input quality
6
6
Most variables have clear descriptions and sensible defaults; validations present for share, telemetry_level, open_in, platform, accept_license. Minor gap: share variable lacks a description field, but overall quality is strong.
Test coverage
4
4
vscode-web.tftest.hcl covers open_in validation logic; main.test.ts extensively covers end-to-end behavior — settings merge (jq/python3/fallback), extension install (explicit list, auto-install from JSONC .vscode/extensions.json and .code-workspace), offline/cached precondition failures, and cache-hit messaging.
IDE Integration — 25 / 25
Criterion
Max
Score
Notes
Dashboard entry point
7
7
coder_app resource defined with icon, healthcheck, open_in, subdomain, and share support — proper launch behavior documented via examples.
Managed configuration
6
6
settings variable documented in "Pre-configure Machine Settings" section, merges with existing machine settings.json on startup.
Configurable folder or workdir
6
6
folder and workspace variables each documented with dedicated examples ("Install VS Code Web to a custom folder", "Open an existing workspace on startup").
Pre-installed extensions (web IDE)
6
6
extensions variable documented in "Install Extensions" example; also supports auto_install_extensions for JSONC-based recommendations (code-level, tested, though not called out in its own README example).
Overall — 82 / 100
Raw 59 / 72 → round(59 / 72 × 100) = 82
Scored against SCORECARD.md on 2026-10-05 with solstice-1.
reacted with thumbs up emoji reacted with thumbs down emoji reacted with laugh emoji reacted with hooray emoji reacted with confused emoji reacted with heart emoji reacted with rocket emoji reacted with eyes emoji
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
A discussion dedicated to the VS Code Web module. Share your thoughts, questions, and feedback here.
Module Scorecard
Drilldown
Presentation & Onboarding — 17 / 17
commit_id, and open an existing.code-workspacefile — all with sensible defaults shown., verified to exist (5.3MB gif).Credential Hygiene — N/A (excluded, 0 pts)
Restricted-Environment Readiness — 7 / 20
https://update.code.visualstudio.com/...andhttps://vscode.download.prss.microsoft.com/...).commit_idonly pins a version,install_prefixonly changes install location — neither replaces the source URL.use_cachedandofflinevariables letrun.shskip the download entirely if a copy is pre-baked atinstall_prefix, but neither variable is mentioned anywhere in the README — functionality exists in code only, undocumented.run.shsource, not the README.run.shnever invokessudo; all operations (install, extension install, settings merge) run as the agent user.Engineering Quality — 10 / 10
share,telemetry_level,open_in,platform,accept_license. Minor gap:sharevariable lacks adescriptionfield, but overall quality is strong.vscode-web.tftest.hclcoversopen_invalidation logic;main.test.tsextensively covers end-to-end behavior — settings merge (jq/python3/fallback), extension install (explicit list, auto-install from JSONC.vscode/extensions.jsonand.code-workspace), offline/cached precondition failures, and cache-hit messaging.IDE Integration — 25 / 25
coder_appresource defined with icon, healthcheck,open_in,subdomain, andsharesupport — proper launch behavior documented via examples.settingsvariable documented in "Pre-configure Machine Settings" section, merges with existing machinesettings.jsonon startup.folderandworkspacevariables each documented with dedicated examples ("Install VS Code Web to a custom folder", "Open an existing workspace on startup").extensionsvariable documented in "Install Extensions" example; also supportsauto_install_extensionsfor JSONC-based recommendations (code-level, tested, though not called out in its own README example).Overall — 82 / 100
Raw 59 / 72 → round(59 / 72 × 100) = 82
Scored against SCORECARD.md on 2026-10-05 with
solstice-1.All reactions