Skip to content

Security: eXPerience83/remote-dev-containers

SECURITY.md

Security Policy

Supported versions

This project is in active experimental development and has no stable release yet. Security fixes are applied to main and, when republished, to the current edge images. Older commit tags and digests are not updated in place.

Reporting a vulnerability

Report suspected vulnerabilities through GitHub Private Vulnerability Reporting:

https://github.com/eXPerience83/remote-dev-containers/security/advisories/new

Do not open a public issue, pull request or discussion containing exploit details, credentials, tokens, private hostnames or infrastructure paths.

Include, where possible:

  • the affected image tag or digest and source commit;
  • the deployment configuration relevant to the issue;
  • clear reproduction steps;
  • the expected and observed behavior;
  • the potential impact and any known mitigation;
  • logs or screenshots with secrets and personal infrastructure details removed.

For general hardening guidance and the current threat model, see docs/security.md.

There aren't any published security advisories