This is the canonical security policy for CocoIndex Code Plus (it is also
vendored into the product repositories via the pub submodule).
Email security@cocoindex.io — please do not open public issues. Process, response SLAs, and disclosure terms are defined in the CocoIndex organization security policy.
CocoIndex Code Plus and its distribution channels:
- PyPI package
cocoindex-code-plus(theccxCLI) - Container images
ghcr.io/cocoindex-io/ccx-query-serverandghcr.io/cocoindex-io/ccx-indexer - The Helm chart (OCI) and the licensed
cocoindex-plusengine wheels
Security fixes land in the latest release; upgrade to the newest version to receive them.
Container images are signed with Sigstore cosign (keyless OIDC) and carry SBOM and build-provenance attestations; the Helm chart is cosign-signed; the CLI is published to PyPI via Trusted Publishing.