Please do not report security vulnerabilities in public GitHub issues or Discord channels. Use GitHub's private vulnerability report so the Command Code team can investigate with you privately.
If GitHub reporting is unavailable, email [email protected]. Include:
- A clear description of the issue and its potential impact
- The affected Command Code GUI version and operating system
- Reproduction steps or a minimal proof of concept
- Any relevant logs with credentials and private project data removed
We will acknowledge the report, investigate it, and coordinate disclosure with you when appropriate.
Version 0.1.0 is an unsigned preview. Use only the direct download link in the
official CommandCodeAI/gui repository
and verify the SHA-256 digest documented in INSTALL.md.
The digest confirms that a download matches the file we published; it does not replace operating-system code signing. Signed and notarized builds are planned for the production release.