Skip to content

Security: SC123667/CodexOpsStudio

Security

SECURITY.md

Security Policy

Supported status

CodexOpsStudio is currently an active prototype. Security fixes will be handled on a best-effort basis.

Reporting a vulnerability

Please do not open public issues for security-sensitive problems.

Instead:

  1. use GitHub private reporting if available
  2. include reproduction details
  3. include affected files or commands
  4. describe whether the issue can impact credentials, Git state, or local file safety

Security scope

Important areas for responsible reporting:

  • command execution boundaries
  • Git worktree isolation
  • Codex CLI process orchestration
  • unsafe file operations
  • GitHub publishing actions
  • path handling for non-ASCII and user-selected repositories

There aren’t any published security advisories