Please do not open a public issue for a suspected vulnerability.
Use GitHub's Report a vulnerability form in the Security tab of this repository. Include the affected version or commit, reproduction steps, impact, and any suggested mitigation. Do not include real provider keys, account tokens, private prompts, or user data.
We will acknowledge a complete report as soon as practical, validate the issue, and coordinate disclosure after a fix is available.
Security fixes target the latest published source and the latest official Codelit Desktop release. Older builds may not receive fixes.
Only releases signed and notarized by Codelit are official Codelit builds. A source checkout, pull request build, ad-hoc build, or fork is not an official release and must not reuse Codelit's signing identity or update channel.