Skip to content

Latest commit

 

History

History
25 lines (17 loc) · 765 Bytes

File metadata and controls

25 lines (17 loc) · 765 Bytes

Security Policy

Reporting a Vulnerability

If you discover a security vulnerability in any AToolZ project, please report it responsibly.

How to report:

What to expect:

  • Acknowledgment within 48 hours
  • Status update within 7 days
  • We'll coordinate disclosure timing with you

Scope

AToolZ projects are VS Code extensions that run locally. The primary risk vectors are:

  • Command injection via extension settings (e.g., binary paths)
  • Malicious workspace configuration files
  • Dependency supply chain

Supported Versions

We provide security updates for the latest published version of each extension.