Skip to content

Security: codelit-io/codelit-desktop

SECURITY.md

Security Policy

Reporting a vulnerability

Please do not open a public issue for a suspected vulnerability.

Use GitHub's Report a vulnerability form in the Security tab of this repository. Include the affected version or commit, reproduction steps, impact, and any suggested mitigation. Do not include real provider keys, account tokens, private prompts, or user data.

We will acknowledge a complete report as soon as practical, validate the issue, and coordinate disclosure after a fix is available.

Supported versions

Security fixes target the latest published source and the latest official Codelit Desktop release. Older builds may not receive fixes.

Release trust

Only releases signed and notarized by Codelit are official Codelit builds. A source checkout, pull request build, ad-hoc build, or fork is not an official release and must not reuse Codelit's signing identity or update channel.

There aren't any published security advisories