Ripieno

Security policy

Ripieno is currently a 0.0.x Preview. When public builds exist, only the latest published Preview is supported; older builds should be upgraded before a report is investigated. Source installs and privately shared VSIX files must identify the exact commit they were built from.

Report a vulnerability privately

If the repository exposes GitHub private vulnerability reporting, use it. Do not put tokens, API keys, private room content, exploit details or private repository contents in a public issue. If private reporting is unavailable, open a minimal security issue that contains no sensitive detail and asks for a private contact route.

Include the Ripieno version or commit, editor and OS, affected configuration, reproduction steps, impact, and whether the issue is already being exploited. Please wait for a fix before publishing exploit details.

Security boundaries

Deployment guidance is in docs/self-hosting.md, data handling is documented in PRIVACY.md, and bundled licenses are in packages/extension/THIRD_PARTY_NOTICES.md.