CodeDiag is currently pre-1.0. Security fixes are applied to the latest
released version and the main branch.
| Version | Supported |
|---|---|
| Latest release | Yes |
| Older releases | No |
Please use GitHub private vulnerability reporting for suspected vulnerabilities. Include:
- the affected version or commit;
- reproduction steps or a minimal proof of concept;
- the expected security impact;
- any suggested mitigation, if known.
Do not include credentials, private source code, or sensitive user data in the report. Please allow a reasonable investigation period before public disclosure. Confirmed reports will receive a status update and remediation plan through the private advisory.
General bugs and analyzer false positives belong in the public issue tracker.