| Version | Supported |
|---|---|
| 1.0.x (CLI) | ✅ |
| 0.1.x (VS Code) | ✅ |
| < 1.0.0 | ❌ |
Please do not open a public GitHub issue for security vulnerabilities.
Use GitHub's private vulnerability reporting to report issues confidentially.
Alternatively, email: jackby03@outlook.com
- Description of the vulnerability
- Steps to reproduce
- Affected component (CLI, VS Code extension, spec)
- Potential impact
- Acknowledgement: within 48 hours
- Status update: within 7 days
- Fix / advisory: within 30 days for confirmed vulnerabilities
Reporters who responsibly disclose vulnerabilities will be credited in the security advisory unless they prefer to remain anonymous.