Skip to content

Security: atoolz/htmx-devtools

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

If you discover a security vulnerability in any AToolZ project, please report it responsibly.

How to report:

What to expect:

  • Acknowledgment within 48 hours
  • Status update within 7 days
  • We'll coordinate disclosure timing with you

Scope

AToolZ projects are VS Code extensions that run locally. The primary risk vectors are:

  • Command injection via extension settings (e.g., binary paths)
  • Malicious workspace configuration files
  • Dependency supply chain

Supported Versions

We provide security updates for the latest published version of each extension.

There aren’t any published security advisories