Skip to content

Security: ymzhang10/codex-capability-advisor

SECURITY.md

Security Policy

Supported versions

Security fixes are applied to the latest released version. Older snapshots are not maintained as separate support branches.

Report a vulnerability

Please report vulnerabilities privately through GitHub Security Advisories. Do not include secrets, tokens, private catalog contents, or sensitive record data in a public issue.

Include only the minimum information needed to reproduce the problem:

  • affected version or commit;
  • operating system and Python version;
  • impact and reproduction steps using synthetic data;
  • whether local paths, credentials, or generated artifacts may have been exposed.

Please allow time for triage before public disclosure. No guaranteed response or remediation timeline is offered.

Scope notes

The project parses metadata from local Codex installations and may invoke the local Codex CLI for live collection. Reports about third-party plugins, apps, MCP servers, marketplaces, or Codex itself should also be sent to the relevant upstream maintainer. This policy covers vulnerabilities in this repository's code and documentation.

There aren't any published security advisories