- Private vulnerability reports: Use GitHub’s “Report a vulnerability” on this repo.
- Email (fallback): security@codesidecar.dev
We acknowledge within 1 business day; target a fix or advisory within 7.
Sensitive disclosures can be encrypted to our security PGP key:
- PGP Fingerprint: 5B17 9C14 4AD6 FFC1 CC15 5F44 375B 6C20 D588 D636
- Public Key: codesidecar-security.asc