Skip to content

Security: SunrisesIllNeverSee/sigrank-vscode

Security

SECURITY.md

Security Policy

Reporting a vulnerability

If you discover a security vulnerability, please do not open a public issue.

Report privately via GitHub Security Advisories.

Scope

  • The VS Code extension
  • The MCP server bridge
  • Local session log reading
  • Privacy guarantees (token-only, no message content)

Out of scope

Response timeline

  • Acknowledgement within 48 hours
  • Assessment within 7 days

There aren't any published security advisories