Security fixes are released for the latest published version of the plugin. Older versions are not patched.
Please do not open a public issue for a security problem.
Report vulnerabilities privately to engineering@elide.dev, or through GitHub's private vulnerability reporting for this repository.
Please include:
- affected plugin version and IDE build,
- a description of the impact,
- reproduction steps or a proof of concept.
You can expect an acknowledgement within three business days, and an assessment with a remediation plan or a rejection rationale within ten business days. Please give us a reasonable opportunity to ship a fix before public disclosure.
This policy covers the plugin in this repository. Vulnerabilities in the Elide runtime and CLI belong in the elide-dev/elide repository; vulnerabilities in the IntelliJ Platform itself should be reported to JetBrains.