We use cookies to make your experience better.
Learn about the tools used to detect vulnerabilities in code-server, and how you can report vulnerabilities.
Coder and the code-server team want to keep the code-server project secure and safe for end-users.
We use the following tools to help us stay on top of vulnerability mitigation.
audit-ci
Audit for vulnerabilities
step
in ci.yaml
) on PRs into the default branch and fails CI if moderate or
higher vulnerabilities (see the audit.sh
script) are present.Coder sponsors the development and maintenance of the code-server project. We will fix security issues within 90 days of receiving a report and publish the fix in a subsequent release. The code-server project does not provide backports or patch releases for security issues at this time.
Version | Supported |
---|---|
Latest | :white_check_mark: |
To report a vulnerability, please send an email to security[@]coder.com, and our security team will respond to you.
See an opportunity to improve our docs? Make an edit.