Skip to content

Latest commit

 

History

History
53 lines (38 loc) · 1.76 KB

SECURITY.md

File metadata and controls

53 lines (38 loc) · 1.76 KB

Security Policy

Supported Versions

The following versions of Claude Code are currently supported with security updates:

Version Supported
0.3.x
0.2.x
< 0.2

Reporting a Vulnerability

We take the security of Claude Code seriously. If you believe you've found a security vulnerability, please follow these steps:

  1. Do not disclose the vulnerability publicly
  2. Open a private vulnerability report through the GitHub repository's Security tab
    • Include steps to reproduce
    • Include potential impact
    • If possible, include suggestions for remediation
  3. Allow time for response and remediation
    • We aim to respond to security reports within 72 hours
    • We'll keep you updated on our progress addressing the issue

Security Response Process

When a security vulnerability is reported:

  1. We will confirm receipt of the vulnerability report
  2. We will investigate and validate the reported issue
  3. We will develop and test a fix
  4. We will release a security update
  5. We will publicly disclose the issue after a fix is available

Security Best Practices for Users

  • Keep Claude Code updated to the latest supported version
  • Regularly update Neovim and related plugins
  • Be cautious when sharing sensitive information with AI assistants
  • Follow the principle of least privilege when configuring Claude Code
  • Review Claude Code's integration with external tools

Security Updates

Security updates will be released as:

  • Patch versions for supported releases
  • Announcements in our release notes
  • Updates to the CHANGELOG.md file

Past Security Advisories

No formal security advisories have been issued for this project yet.