mrkeyoor.com_
Tue 06 Oct 04:14 UTC
Dev Toolsevaluationupdated 06 Oct 2026

vscodium review

VSCodium publishes community-built binaries from Microsoft's open-source VS Code codebase, with Microsoft branding and telemetry endpoints removed. It gives developers the familiar VS Code interface under an MIT-licensed distribution, while changing the default extension registry and some Microsoft-specific integrations.

Verdict

Our run installed 316 packages in 9 seconds and reported 6 known vulnerabilities in the font-size helper, so it did not prove that the VSCodium editor builds cleanly. Use VSCodium when the VS Code interface, MIT binaries, and disabled telemetry settings outweigh Open VSX gaps and Microsoft-extension limits. Test search, remote work, debugging, and every required extension on the exact release before standardizing it across a team.

We ran it

Lab card: what happened when we ran vscodiumScreenshot of vscodium (vscodium.com)
Install✓ · 9s316 packages · 117 MB
Buildn/ano build script
Testsn/ano test script
Known vulns60 critical · 5 high · 1 moderate · 0 low (npm audit)
Repo407 files~4,682 lines of source · 32 MB · 15 CI workflows

Answers from our run

Does vscodium build from source?

Dependencies installed in 9 seconds (316 packages), and the project has no separate build step. We cloned commit 3465455 into a clean Debian container with 3 CPUs and no project-specific setup.

Does vscodium have tests you can run?

Not through a standard command: the project exposes no test script or target that our harness could run.

Does vscodium have known vulnerabilities in its dependencies?

npm audit flagged 6 known advisories in the dependency tree at the time of our run.

Who should not use vscodium?

Developers dependent on proprietary Microsoft extensions or debuggers: the project documents C#, C++, and Remote Development restrictions outside official VS Code.

What are the alternatives to vscodium?

Visual Studio Code, code-server, Zed. Our run installed 316 packages in 9 seconds and reported 6 known vulnerabilities in the font-size helper, so it did not prove that the VSCodium editor builds cleanly.

Setup4/5Many binary options; source distribution builds are a separate job
Docs4/5Clear install, telemetry, marketplace, and platform guidance
Community5/533,517 stars, an October 5 push, and current issue activity
Maturity4/5Active since 2018, with broad releases and some current regressions

Discussed on

  1. hnVSCodium – Free/Libre Open Source Software Binaries of VS Code723 points
  2. hnVSCodium – Open-source binaries of VSCode486 points
  3. hnVSCodium – An Open Source Visual Studio Code Without Trackers464 points
  4. hnVS Code without Microsoft branding/telemetry/licensing369 points
  5. hnVSCodium: Binary releases of VSCode without MS branding, telemetry and licensing266 points

Who it’s for

Developers who like VS Code's interface but want community-built, MIT-licensed binaries with telemetry settings disabled.
Linux users who prefer distribution packages, Flatpak, Snap, AppImage, or direct archives.
Organizations prepared to approve extensions from Open VSX or operate a private extension gallery.
Teams that can test their exact extensions and remote workflows before a wider rollout.

Who it’s NOT for

Developers dependent on proprietary Microsoft extensions or debuggers: the project documents C#, C++, and Remote Development restrictions outside official VS Code.
Teams that require the Visual Studio Marketplace as the supported default: VSCodium uses Open VSX because Microsoft's terms restrict other products.
Buyers who interpret telemetry-disabled as zero network traffic: update checks, announcements, extension safety data, and extension-owned telemetry can still make connections.
Release engineers seeking proof that this checkout built the editor: our run only installed ./font-size, where no build or test target existed.
Organizations that cannot accept 6 audit findings in the measured npm helper, including 5 high-severity findings.

Setup reality

Our sandbox entered ./font-size at commit 3465455 and installed 316 npm packages in 9 seconds, using 117 MB. That package had no build script and no test script, so both steps were skipped. Npm audit reported 6 known vulnerabilities: 5 high and 1 moderate.

Most users install a signed release or use a package manager and need no credential. Building the distribution is a different job: the scripts fetch Microsoft's VS Code source, Electron, FFmpeg, and prebuilt debugger extensions, then package platform-specific binaries. Our run did not exercise that path.

The README supports macOS 12 or newer and Windows 10 or newer, plus several Linux architectures. Linux app self-updates are disabled at build time in favor of package managers. Open VSX is the default extension registry, and some Microsoft-licensed extensions do not work in VSCodium.

VSCodium rebuilds VS Code with MIT binaries and telemetry disabled

VSCodium takes Microsoft's open-source VS Code repository, applies a community product.json and patches, then publishes binaries without Microsoft branding or configured telemetry endpoints. The project describes itself as automated build scripts rather than a fork. That matters because editor features still come largely from upstream VS Code, while VSCodium owns the distribution choices, packaging, update services, and extension registry defaults.

Our measured checkout had 407 files, about 4,682 lines of source, and occupied 32 MB. That is small because this repository does not contain the full VS Code source tree. Its scripts fetch upstream code and other build inputs when producing a release. The README lists Electron, FFmpeg, and several prebuilt debugging extensions among those inputs, so rebuilding the published desktop packages is much broader than cloning these 407 files.

Open VSX is the main compatibility tradeoff

VSCodium points its extension view at Open VSX. The project cites Microsoft's Marketplace terms, which limit Marketplace offerings to Visual Studio products and services. Open VSX covers many common tools and can be replaced with another gallery or a self-hosted registry. It is still a different catalog, with different publication timing and availability. Check every extension ID your work depends on before moving a team.

The 316 packages in our npm install belonged to ./font-size, a helper that generates CSS during packaging. They say nothing about whether a Python, C#, C++, or remote-development extension works. VSCodium's documentation specifically warns that Microsoft C# and Windows C++ debuggers have restrictive licenses, and that Remote Development extensions may function only in official VS Code. Workarounds exist for some cases, but they are extra engineering rather than drop-in parity.

What happened when we ran it

Our sandbox installed commit 3465455's ./font-size project in 9 seconds. Npm added 316 packages and the installed tree occupied 117 MB. The container supplied 3 CPUs, 8 GB of RAM, Node 22, no secrets, and no elevated privileges. Installation succeeded, but this was the nested CSS-generation project identified by the lab harness. We did not build or launch a VSCodium editor binary.

The package exposed no build script and no test script, so our run skipped both steps. Npm audit found 6 known vulnerabilities: 5 high and 1 moderate, with no critical or low findings. The repository scan found 15 CI workflow files, no Dockerfile, and no tests directory. Those results are useful for judging the measured helper and visible repository controls. They cannot stand in for a desktop smoke test or the upstream VS Code suite.

Disabled telemetry still permits several network connections

VSCodium disables seven named telemetry and experimentation settings by default, including crash reporting and edit statistics. Its build replaces the Microsoft update URL with GitHub and the Visual Studio Marketplace with Open VSX. This materially changes the default network path. The telemetry guide still tells users to inspect settings tagged usesOnlineServices, because editor functions and installed extensions can contact outside services.

The 6 audit findings in our 117 MB helper install are separate from runtime telemetry, yet both facts point to the same policy lesson: inspect the exact artifact you deploy. VSCodium checks for application and extension updates, fetches welcome-page announcements, and downloads an extension safety list unless you change settings. Extensions can send their own telemetry, which the project cannot disable centrally. Air-gapped or tightly filtered networks need a tested configuration, not the default install alone.

October activity shows maintenance alongside release regressions

The repository was pushed on October 5, 2026, and GitHub listed 33,517 stars plus 156 open issues and pull requests combined. The latest release, 1.135.06055, was published on September 9 with packages for Windows, macOS, and several Linux architectures. Issues opened after that release include a VSCodium-specific workspace-search regression and missing on-device dictation runtime metadata. Current pushes and current bug reports show active maintenance, not a quiet project.

The repository also had 15 CI workflow files at commit 3465455, but our scan found no tests directory and the measured npm project offered no test target. That split is understandable for a distribution project whose release matrix spans x64, Arm, RISC-V, PowerPC, and LoongArch. It also means buyers should install the exact format they intend to support. A Snap-specific external-link issue, for example, says little about the .deb or macOS package.

Check the extension list before choosing the distribution

VSCodium is an easy recommendation for an individual who already knows that required extensions exist on Open VSX. Package choices cover mainstream desktop systems and several less common Linux architectures, telemetry defaults are documented, and the interface remains close to VS Code. For a company, run a pilot with debugging, Settings Sync replacements, remote access, search, and update behavior before making it the standard image.

Our 9-second run and 117 MB install show that the font-size helper resolves on Node 22; the missing build and test targets leave the editor unverified by this lab run. That is the honest stopping point. Choose VSCodium for its distribution policy, then validate the actual binary and workflow you will use, especially when a proprietary Microsoft extension sits anywhere on the critical path.

Alternatives

ProjectWhat it isPick it when
Visual Studio Code gh↗Microsoft's upstream editor source, paired with official binaries and Microsoft services.pick this instead when official Marketplace access and Microsoft-only extensions matter more than the VSCodium distribution changes.
code-server gh↗A browser-accessible VS Code environment designed to run on a remote machine.pick this instead when remote browser access is the main requirement rather than a local desktop editor.
Zed gh↗A native code editor with its own interface, collaboration model, and extension ecosystem.pick this instead when you want a native editor and can leave VS Code extension compatibility behind.

What people are saying

  1. [velocity-scout] VSCodium/vscodium

Sources

  1. VSCodium README
  2. Extensions and Marketplace documentation
  3. Telemetry documentation
  4. Release 1.135.06055
  5. Issue 3013: workspace search regression
  6. Issue 3045: on-device dictation runtime
  7. Repository facts

More dev tools reviews

hyperfine · stripe-cli · build123d · OpenCore-Legacy-Patcher · cli · learning-python · the whole board →