Skip to content

Security: Gringo2/Dimension-MonoRepo

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

We take the security of Codesphere seriously. Given that Codesphere is a distribution of VS Code, vulnerabilities can exist either at the distribution layer (our scripts and configurations) or the core IDE layer.

How to Report

Please do not open public issues for security vulnerabilities. Instead, send a detailed report to our security contact (e.g., security@codesphere-ide.org or via GitHub Private Vulnerability Reporting if enabled).

Your report should include:

  • A description of the vulnerability.
  • Steps to reproduce (Proof of Concept).
  • Potential impact.

Supported Versions

We support the latest release of Codesphere based on the current stable version of VSCodium. We recommend all users keep their IDE up-to-date to benefit from upstream security patches.

Sovereignty Audit

One of the primary goals of Codesphere is to eliminate third-party telemetry. If you discover a previously unknown network connection to a corporate endpoint, we treat this as a high-priority privacy bug.


Codesphere: Built for developers who value security and sovereignty.

There aren’t any published security advisories