The following table shows which versions of MageForge for VS Code currently receive security updates.
| Version | Supported | Notes |
|---|---|---|
| 0.4.x | ✅ | Current release line |
| 0.3.x | ❌ | No longer supported; please upgrade to 0.4.x |
| < 0.3.0 | ❌ | No longer supported |
We generally support the latest minor release of the current major version. When a new version is published, the previous release line stops receiving security updates after a short grace period. Users are encouraged to keep the extension up to date through the VS Code Marketplace.
If you discover a security vulnerability in MageForge for VS Code, please report it responsibly.
Use GitHub Security Advisories to privately report a vulnerability:
- Go to the repository: https://github.com/OpenForgeProject/mageforge-vscode
- Open the Security tab
- Click Report a vulnerability
- Fill in the advisory form with as much detail as possible (steps to reproduce, impact, affected versions)
Please do not open a public issue for security problems.
- Acknowledgement: We will acknowledge receipt of your report within 5 business days.
- Investigation: We will investigate and validate the vulnerability. We may ask you for additional information or a proof of concept.
- Resolution timeline: We aim to release a fix within 30 days for confirmed vulnerabilities. Complex issues may take longer; if so, we will keep you informed.
- Coordinated disclosure: Once a fix is released, we will publish a security advisory and credit you as the reporter, unless you prefer to remain anonymous.
- Declined reports: If we determine the report is not a valid security issue, we will explain our reasoning and, if appropriate, close the advisory privately.
Thank you for helping keep MageForge and its users secure.