Skip to content

Security: OpenForgeProject/mageforge-vscode

SECURITY.md

Security Policy

Supported Versions

The following table shows which versions of MageForge for VS Code currently receive security updates.

Version Supported Notes
0.4.x Current release line
0.3.x No longer supported; please upgrade to 0.4.x
< 0.3.0 No longer supported

We generally support the latest minor release of the current major version. When a new version is published, the previous release line stops receiving security updates after a short grace period. Users are encouraged to keep the extension up to date through the VS Code Marketplace.

Reporting a Vulnerability

If you discover a security vulnerability in MageForge for VS Code, please report it responsibly.

Preferred channel

Use GitHub Security Advisories to privately report a vulnerability:

  1. Go to the repository: https://github.com/OpenForgeProject/mageforge-vscode
  2. Open the Security tab
  3. Click Report a vulnerability
  4. Fill in the advisory form with as much detail as possible (steps to reproduce, impact, affected versions)

Please do not open a public issue for security problems.

What to expect

  • Acknowledgement: We will acknowledge receipt of your report within 5 business days.
  • Investigation: We will investigate and validate the vulnerability. We may ask you for additional information or a proof of concept.
  • Resolution timeline: We aim to release a fix within 30 days for confirmed vulnerabilities. Complex issues may take longer; if so, we will keep you informed.
  • Coordinated disclosure: Once a fix is released, we will publish a security advisory and credit you as the reporter, unless you prefer to remain anonymous.
  • Declined reports: If we determine the report is not a valid security issue, we will explain our reasoning and, if appropriate, close the advisory privately.

Thank you for helping keep MageForge and its users secure.

There aren't any published security advisories