Skip to content

Security: CommandCodeAI/gui

SECURITY.md

Security

Please do not report security vulnerabilities in public GitHub issues or Discord channels. Use GitHub's private vulnerability report so the Command Code team can investigate with you privately.

If GitHub reporting is unavailable, email [email protected]. Include:

  • A clear description of the issue and its potential impact
  • The affected Command Code GUI version and operating system
  • Reproduction steps or a minimal proof of concept
  • Any relevant logs with credentials and private project data removed

We will acknowledge the report, investigate it, and coordinate disclosure with you when appropriate.

Preview-build safety

Version 0.1.0 is an unsigned preview. Use only the direct download link in the official CommandCodeAI/gui repository and verify the SHA-256 digest documented in INSTALL.md.

The digest confirms that a download matches the file we published; it does not replace operating-system code signing. Signed and notarized builds are planned for the production release.

There aren't any published security advisories