We use cookies to make your experience better.
Learn about the tools used to detect vulnerabilities in code-server, and how you can report vulnerabilities.
Coder and the code-server team want to keep the code-server project secure and safe for end-users.
We use the following tools to help us stay on top of vulnerability mitigation.
audit-ci
Audit for vulnerabilities step
in ci.yaml) on PRs into the default branch and fails CI if moderate or
higher vulnerabilities (see the audit.sh script) are present.Coder sponsors the development and maintenance of the code-server project. We will fix security issues within 90 days of receiving a report and publish the fix in a subsequent release. The code-server project does not provide backports or patch releases for security issues at this time.
| Version | Supported | 
|---|---|
| Latest | :white_check_mark: | 
To report a vulnerability, please send an email to security[@]coder.com, and our security team will respond to you.
See an opportunity to improve our docs? Make an edit.