Security updates are provided for the latest released version on master branch / released in VS Code marketplace.
| Version | Supported |
|---|---|
| latest | Yes |
| older | No |
Please do not open public GitHub issues for security vulnerabilities.
Instead, report vulnerabilities privately by emailing:
Please include as much detail as possible:
- A clear description of the issue and potential impact
- Steps to reproduce
- A minimal proof of concept, if available
- Affected versions, configuration, and environment details
- Initial acknowledgment: within 7 days
- Follow-up after triage: as soon as practical
- Fix timeline: depends on severity and complexity
If the report is accepted, a fix will be prepared and released. Credit can be provided in release notes if requested.
This policy applies to the source code and release artifacts in this repository.