VSCodium rebuilds VS Code with MIT binaries and telemetry disabled
VSCodium takes Microsoft's open-source VS Code repository, applies a community product.json and patches, then publishes binaries without Microsoft branding or configured telemetry endpoints. The project describes itself as automated build scripts rather than a fork. That matters because editor features still come largely from upstream VS Code, while VSCodium owns the distribution choices, packaging, update services, and extension registry defaults.
Our measured checkout had 407 files, about 4,682 lines of source, and occupied 32 MB. That is small because this repository does not contain the full VS Code source tree. Its scripts fetch upstream code and other build inputs when producing a release. The README lists Electron, FFmpeg, and several prebuilt debugging extensions among those inputs, so rebuilding the published desktop packages is much broader than cloning these 407 files.
Open VSX is the main compatibility tradeoff
VSCodium points its extension view at Open VSX. The project cites Microsoft's Marketplace terms, which limit Marketplace offerings to Visual Studio products and services. Open VSX covers many common tools and can be replaced with another gallery or a self-hosted registry. It is still a different catalog, with different publication timing and availability. Check every extension ID your work depends on before moving a team.
The 316 packages in our npm install belonged to ./font-size, a helper that generates CSS during packaging. They say nothing about whether a Python, C#, C++, or remote-development extension works. VSCodium's documentation specifically warns that Microsoft C# and Windows C++ debuggers have restrictive licenses, and that Remote Development extensions may function only in official VS Code. Workarounds exist for some cases, but they are extra engineering rather than drop-in parity.
What happened when we ran it
Our sandbox installed commit 3465455's ./font-size project in 9 seconds. Npm added 316 packages and the installed tree occupied 117 MB. The container supplied 3 CPUs, 8 GB of RAM, Node 22, no secrets, and no elevated privileges. Installation succeeded, but this was the nested CSS-generation project identified by the lab harness. We did not build or launch a VSCodium editor binary.
The package exposed no build script and no test script, so our run skipped both steps. Npm audit found 6 known vulnerabilities: 5 high and 1 moderate, with no critical or low findings. The repository scan found 15 CI workflow files, no Dockerfile, and no tests directory. Those results are useful for judging the measured helper and visible repository controls. They cannot stand in for a desktop smoke test or the upstream VS Code suite.
Disabled telemetry still permits several network connections
VSCodium disables seven named telemetry and experimentation settings by default, including crash reporting and edit statistics. Its build replaces the Microsoft update URL with GitHub and the Visual Studio Marketplace with Open VSX. This materially changes the default network path. The telemetry guide still tells users to inspect settings tagged usesOnlineServices, because editor functions and installed extensions can contact outside services.
The 6 audit findings in our 117 MB helper install are separate from runtime telemetry, yet both facts point to the same policy lesson: inspect the exact artifact you deploy. VSCodium checks for application and extension updates, fetches welcome-page announcements, and downloads an extension safety list unless you change settings. Extensions can send their own telemetry, which the project cannot disable centrally. Air-gapped or tightly filtered networks need a tested configuration, not the default install alone.
October activity shows maintenance alongside release regressions
The repository was pushed on October 5, 2026, and GitHub listed 33,517 stars plus 156 open issues and pull requests combined. The latest release, 1.135.06055, was published on September 9 with packages for Windows, macOS, and several Linux architectures. Issues opened after that release include a VSCodium-specific workspace-search regression and missing on-device dictation runtime metadata. Current pushes and current bug reports show active maintenance, not a quiet project.
The repository also had 15 CI workflow files at commit 3465455, but our scan found no tests directory and the measured npm project offered no test target. That split is understandable for a distribution project whose release matrix spans x64, Arm, RISC-V, PowerPC, and LoongArch. It also means buyers should install the exact format they intend to support. A Snap-specific external-link issue, for example, says little about the .deb or macOS package.
Check the extension list before choosing the distribution
VSCodium is an easy recommendation for an individual who already knows that required extensions exist on Open VSX. Package choices cover mainstream desktop systems and several less common Linux architectures, telemetry defaults are documented, and the interface remains close to VS Code. For a company, run a pilot with debugging, Settings Sync replacements, remote access, search, and update behavior before making it the standard image.
Our 9-second run and 117 MB install show that the font-size helper resolves on Node 22; the missing build and test targets leave the editor unverified by this lab run. That is the honest stopping point. Choose VSCodium for its distribution policy, then validate the actual binary and workflow you will use, especially when a proprietary Microsoft extension sits anywhere on the critical path.

