If you discover a security vulnerability in BeadsX, please report it responsibly:
- Do NOT open a public issue for security vulnerabilities
- Email: Send details to the maintainer via GitHub's private vulnerability reporting feature, or open a private security advisory
- Include: Description of the vulnerability, steps to reproduce, and potential impact
- Acknowledgment: Within 48 hours
- Initial assessment: Within 7 days
- Fix timeline: Depends on severity, typically within 30 days for critical issues
This security policy applies to:
- The BeadsX VSCode extension
- The source code in this repository
- The
bdCLI tool (report issues to beads repository) - Third-party dependencies (report to respective maintainers)
| Version | Supported |
|---|---|
| 0.2.x | ✅ |
| < 0.2 | ❌ |