Skip to content

Security: Fisherk2/codice-opencode

Security

docs/SECURITY.md

Security Policy — Códice

Supported Versions

Version Supported
1.2.x ✅ Supported
1.1.x ✅ Supported
1.0.x ✅ Supported
< 1.0 ❌ No longer supported

Reporting a Vulnerability

Please do not report security vulnerabilities through public GitHub issues.

Instead, report them privately through GitHub Security Advisories or by email to dev@fisherk2.com.

You should receive a response within 48 hours. If you do not receive a response, please follow up to ensure we received your original message.

Response Process

  1. Acknowledgment — within 48 hours of report
  2. Triage — within 5 business days (confirm vulnerability and assess severity)
  3. Fix and Disclosure — timeline based on severity:
    • Critical/High — patch released within 7 days
    • Medium — patch released within 30 days
    • Low — patch released in next regular release cycle

Disclosure Policy

We follow coordinated disclosure:

  • Reporters are credited in security advisories upon request
  • Critical fixes are released as patch versions
  • Security advisories are published via GitHub Security Advisories
  • We coordinate the public disclosure date with the reporter

There aren't any published security advisories