Only the latest released version of each component is supported with security fixes:
- VS Code extension — latest version published on the VS Code Marketplace and Open VSX Registry
- CLI — latest version published on npm
- JetBrains plugin — latest version published on the JetBrains Marketplace
- Visual Studio extension — latest version published on the Visual Studio Marketplace
Older releases do not receive security patches. Please upgrade to the latest version before reporting a vulnerability.
If you discover a security vulnerability in this project, please do not open a public GitHub issue.
Instead, report it privately using GitHub's private vulnerability reporting feature. This creates a private draft security advisory that only the maintainers can see, so the issue can be discussed and fixed before it's disclosed publicly.
Please include as much detail as possible:
- A description of the vulnerability and its potential impact
- Steps to reproduce it (affected component, version, and environment)
- Any relevant logs, screenshots, or proof-of-concept code
We aim to acknowledge reports promptly and will keep you updated as the issue is investigated and resolved.
- Secret scanning is enabled on this repository.
- Dependencies are kept up to date via Dependabot and reviewed with
dependency-reviewon pull requests.
For general bug reports and support questions that are not security-related, please use GitHub Issues as described in SUPPORT.md.