Skip to content

Security: npci/ainxt-code

SECURITY.md

Security Policy

Reporting a Vulnerability

Please do not open a public GitHub issue for security vulnerabilities.

Use this repository's private security advisory. Open the Security tab and click "Report a vulnerability". The report stays confidential between you and the maintainers until a fix is published, and GitHub handles CVE assignment if one is warranted.

If you cannot use a GitHub advisory, email opensource@npci.org.in. It is a monitored group address rather than an individual mailbox, so a report does not depend on one person still being here to read it. The same address is listed as the security contact in MAINTAINERS.md.

The private advisory is still preferred where you have the option. It keeps the report confidential until a fix is published, keeps the discussion attached to the code, and lets GitHub handle CVE assignment. Email is the fallback for reporters who would rather not use a GitHub account, or who need to send an attachment.

Please include:

  • The affected component (VS Code extension, IntelliJ host, or webview)
  • The version of the plugin and of your IDE
  • Steps to reproduce, ideally with a minimal example
  • What an attacker gains — the impact matters more than the severity label

What to expect: an acknowledgement within 3 business days, an initial assessment within 10 business days, and progress updates until the issue is resolved. We will credit you in the advisory unless you prefer otherwise.

Please give us a reasonable window to ship a fix before disclosing publicly.

There aren't any published security advisories