Güvenlik açığı için herkese açık issue veya Discussions gönderisi açmayın. Bildirimi özel kanaldan yapın:
→ Güvenlik danışmanlığı aç (GitHub Security Advisories)
Bu form yalnızca depo yöneticilerine görünür. Konuşma, düzeltme yayımlanana kadar özel kalır.
GitHub hesabınız yoksa veya form size kapalıysa, hiçbir teknik ayrıntı yazmadan
Güvenlik: özel kanal talebi başlıklı bir issue açın; size özel bir iletişim yolu veririz. Açığın
kendisini o issue'da anlatmayın.
- Etkilenen sürüm (editörde
Yardım → Hakkındaekranındaki sürüm numarası) - Windows sürümü ve mimarisi
- Sorunun ne olduğu ve saldırganın ne kazandığı
- Adım adım yeniden üretme yolu — mümkünse en küçük örnek dosya/proje
- Varsa günlük çıktısı, çökme kaydı, ekran görüntüsü
Yeniden üretilebilir bir adım listesi, en iyi yazılmış açıklamadan daha değerlidir.
- Bildiriminizi alır ve doğrulamaya çalışırız.
- Doğrulanırsa düzeltmeyi hazırlar, yeni bir sürüm yayımlarız.
- Sürümle birlikte bir güvenlik danışmanlığı (advisory) yayımlanır; aksini istemezseniz bulan kişi olarak adınız/kullanıcı adınız anılır.
Bu proje tek kişi tarafından yürütülüyor. Yanıt süresi taahhüdü vermiyoruz — gerçek olmayan bir süre yazmaktansa bunu açıkça söylemeyi tercih ediyoruz. Bildiriminiz sırayla okunur ve yanıtlanır.
Ödül programımız yok, para ödülü veremiyoruz.
| Kapsam içinde | Kapsam dışında |
|---|---|
| Editörün kendisi (bu depodan yayımlanan yapı) | Open VSX'ten kurduğunuz üçüncü taraf eklentiler |
| Releases'teki kurulum dosyası, kurulum davranışı | Üst projede bulunan ve henüz üst projede düzeltilmemiş açıklar |
code.talkdedsec.com sitesi |
Gömülü ajanın bağlandığı sağlayıcı servisi (Anthropic'e bildirin) |
| Bu depodaki yapılandırma ve iş akışı dosyaları | Sosyal mühendislik, fiziksel erişim, DoS senaryoları |
Üst projeden devralınan bir açık bulursanız yine de bize haber verin; hem yapımızı etkileyip etkilemediğine bakarız hem de sizi doğru yere yönlendirebiliriz.
Yalnızca Releases'teki en son sürüm güvenlik düzeltmesi alır. Eski sürümlere geriye dönük yama yayımlanmaz — güncel sürüme geçin.
Kurulum dosyası yalnızca bu deponun Releases sayfasından dağıtılır. Başka bir siteden, aynalardan veya paylaşım bağlantılarından indirdiğiniz dosya bizim yayınımız değildir; böyle bir dağıtım görürseniz bildirin.
Do not open a public issue or Discussions post for a security vulnerability. Report it privately:
→ Open a security advisory (GitHub Security Advisories)
That form is visible only to repository maintainers. The thread stays private until a fix is published.
If you do not have a GitHub account or the form is unavailable to you, open an issue titled
Security: private channel request with no technical details at all, and we will give you a private
contact route. Do not describe the vulnerability in that issue.
- Affected version (the version number shown under
Help → Aboutin the editor) - Windows version and architecture
- What the issue is and what an attacker gains
- Step-by-step reproduction — the smallest sample file/project you can manage
- Logs, crash records or screenshots if you have them
A reproducible list of steps is worth more than the best-written description.
- We receive your report and try to reproduce it.
- If confirmed, we prepare a fix and publish a new release.
- A security advisory is published alongside that release; unless you prefer otherwise, you are credited by name or handle.
This project is run by one person. We do not promise a response time — we would rather say so plainly than publish a number that is not real. Reports are read and answered in order.
There is no bug bounty; we cannot offer monetary rewards.
| In scope | Out of scope |
|---|---|
| The editor itself (builds published from this repository) | Third-party extensions you install from Open VSX |
| The installer on Releases and its install behaviour | Upstream vulnerabilities not yet fixed upstream |
The code.talkdedsec.com website |
The provider service the embedded agent connects to (report to Anthropic) |
| Configuration and workflow files in this repository | Social engineering, physical access, DoS scenarios |
If you find a vulnerability inherited from upstream, tell us anyway; we will check whether our build is affected and point you to the right place.
Only the latest release on Releases receives security fixes. Older versions are not back-patched — please update.
The installer is distributed only from this repository's Releases page. A file downloaded from another site, a mirror or a shared link is not our build; if you see such a distribution, report it.