Skip to content

Security: ATC-O48/Claude-OpenAI-Code

Security

SECURITY.md

Security Policy

Supported Versions

Version Supported
Latest Yes

Reporting a Vulnerability

We take security seriously. If you discover a security vulnerability in Workspace IDE, please report it responsibly.

How to Report

  1. Do NOT open a public issue for security vulnerabilities.
  2. Email your report to the maintainers via the ATC-O48 organization contact.
  3. Include the following in your report:
    • Description of the vulnerability
    • Steps to reproduce
    • Potential impact
    • Suggested fix (if any)

What to Expect

  • Acknowledgment within 48 hours of your report.
  • Status update within 7 days with an assessment.
  • Fix timeline based on severity:
    • Critical: Patch within 24-48 hours
    • High: Patch within 1 week
    • Medium: Patch within 2 weeks
    • Low: Included in next release

Scope

This policy applies to the Workspace IDE application and its dependencies. Issues in third-party dependencies should be reported to the respective projects.

Security Best Practices

When contributing to this project:

  • Never commit secrets, API keys, or credentials
  • Use the built-in Secrets tool for managing sensitive data
  • Follow the principle of least privilege
  • Keep dependencies up to date

There aren't any published security advisories