Skip to content

Security: cmdOS-app/cmdOS

Security

SECURITY.md

Security Policy

Supported Versions

Only the latest release of the TaskLabs open-source extension is supported for security updates. If you find a security issue, please ensure you are testing against the latest version on the main branch.


Reporting a Vulnerability

We take the security of TaskLabs seriously. If you find a security vulnerability, please do NOT open a public issue. Instead, report it privately.

To report a vulnerability:

  • Send an email detailing the vulnerability to security@tasklabs.com (or contact the maintainers via the support channel).
  • Include a detailed description of the issue, steps to reproduce, and any proof of concept (PoC) scripts or screenshots.

We will acknowledge your report within 48 hours and work with you to analyze and patch the vulnerability before releasing a public advisory.


Scope of Protection

This security policy covers:

  • The core local-first storage and encryption algorithms.
  • Permissions and Content Security Policies (CSP) defined in the extension manifest.
  • Safe handling of credentials and API keys in user-configured integrations.

There aren't any published security advisories