Skip to content

Latest commit

 

History

History
38 lines (25 loc) · 2.13 KB

File metadata and controls

38 lines (25 loc) · 2.13 KB

Security Policy

Supported Versions

The following table shows which versions of MageForge for VS Code currently receive security updates.

Version Supported Notes
0.4.x Current release line
0.3.x No longer supported; please upgrade to 0.4.x
< 0.3.0 No longer supported

We generally support the latest minor release of the current major version. When a new version is published, the previous release line stops receiving security updates after a short grace period. Users are encouraged to keep the extension up to date through the VS Code Marketplace.

Reporting a Vulnerability

If you discover a security vulnerability in MageForge for VS Code, please report it responsibly.

Preferred channel

Use GitHub Security Advisories to privately report a vulnerability:

  1. Go to the repository: https://github.com/OpenForgeProject/mageforge-vscode
  2. Open the Security tab
  3. Click Report a vulnerability
  4. Fill in the advisory form with as much detail as possible (steps to reproduce, impact, affected versions)

Please do not open a public issue for security problems.

What to expect

  • Acknowledgement: We will acknowledge receipt of your report within 5 business days.
  • Investigation: We will investigate and validate the vulnerability. We may ask you for additional information or a proof of concept.
  • Resolution timeline: We aim to release a fix within 30 days for confirmed vulnerabilities. Complex issues may take longer; if so, we will keep you informed.
  • Coordinated disclosure: Once a fix is released, we will publish a security advisory and credit you as the reporter, unless you prefer to remain anonymous.
  • Declined reports: If we determine the report is not a valid security issue, we will explain our reasoning and, if appropriate, close the advisory privately.

Thank you for helping keep MageForge and its users secure.