Security policy
Report vulnerabilities privately.
Report vulnerabilities privately; the policy below is the one in the repository.
Rendered from SECURITY.md in the repository, so this page and that file are always the same text.
If you find a vulnerability in Sirius — the editor, the sirius-ai extension, the update
server, the release pipeline or this repository — please report it privately.
Please do not report security vulnerabilities through public GitHub issues, discussions or pull requests.
How to report
Use GitHub’s private vulnerability reporting for this repository:
https://github.com/sirius-ide/sirius-ide/security/advisories/new
It opens a draft advisory that only you and the maintainer can see. Include what you
can of: the Sirius version (Help → About, or sirius --version), the platform and how
you installed it, steps to reproduce, and the impact as you understand it. A proof of
concept helps; a working exploit is not required.
You will hear back from the maintainer in the same advisory thread. Fixes ship as a new release, noted in that release’s notes; the advisory is published once a fixed version is available, with credit to you unless you prefer otherwise.
Scope
- In scope: everything this repository builds and publishes — the Sirius desktop
editor, the
sirius-serverremote server, thesirius-aiextension and its model providers, the update server (build/update-server/), the release workflow and the packages it produces, and the download CDN and pacman repository it publishes to. - Upstream Code - OSS: Sirius is a fork of Code - OSS. A vulnerability in the upstream editor affects Sirius too, so report it to us as well as to Microsoft, under their policy at https://aka.ms/SECURITY.md, and we will ship the fix when it lands.
- Third-party model providers and extensions from Open VSX are outside this policy; report those to their maintainers.
Supported versions
Only the latest release receives fixes. Releases are tags on the sirius branch; there
are no maintenance branches. The editor tells you when a newer release exists, and
package-manager installs update with the package manager (see
INSTALL.md).
Verifying what you run
Every release asset is attested with GitHub’s build provenance and carries a .sha256
sidecar. Verify a download with:
gh attestation verify <file> --owner sirius-ide