Wenn Sie eine Sicherheitslücke finden, melden Sie diese bitte verantwortungsvoll:
- Kein öffentliches Issue eröffnen
- GitHub Private Vulnerability Reporting verwenden (
Security→Advisories→New) - Beschreibung, Reproduktionsschritte und potenzielle Auswirkungen angeben
Falls Private Vulnerability Reporting noch nicht aktiviert ist, kontaktieren Sie die Maintainer direkt über GitHub und veröffentlichen Sie keine Details in einem öffentlichen Issue.
Dieses Tool führt sicherheitsrelevante lokale Operationen aus:
- Dateisystem: Lesen/Schreiben der lokalen SQLite-Logdatenbank, Backups, Konfiguration und Logs
- Prozesse: gezieltes Beenden hängender Codex-Desktop-Prozesse (Prozessbaum). Die node-basierte Codex-CLI wird niemals als Beendigungsziel erfasst; ein breiter read-only Prozessnachweis blockiert jedoch Thread-Store-Mutationen, solange Desktop oder CLI aktiv sind.
- Windows-AppX/Store: Registrieren/Zurücksetzen des Codex-Store-Pakets (elevated), Öffnen der Store-Produktseite
- Normale Laufzeit nur lokal: keine Telemetrie, keine Cloud-Synchronisation,
keine Hintergrund-Uploads und keine externen API-Aufrufe (das Öffnen der
Microsoft-Store-Seite ist nur eine lokale Betriebssystemaktion). Der separate
Befehl
store-materials --live-pagesist ein ausdrücklich manueller Release- Vorabcheck; nur dieser Opt-in-Pfad ruft konfigurierte Store-URLs über HTTPS ab und liefert ein eigenes Warnungs-/Fehlerergebnis. Er wird nie vom Tray, Wächter, Wartungsloop oder den Standard-CLI-Befehlen aufgerufen.
- Eingangsbestätigung (Response SLA): Wir bestätigen den Eingang von Sicherheitsmeldungen verbindlich innerhalb von 48 Stunden (48 hours).
- Triage & Risikobewertung: Eine erste technische Triage und Risikobewertung erfolgt innerhalb von 5 Werktagen (5 business days).
- Veröffentlichung: Kritische Probleme werden priorisiert. Bitte geben Sie ausreichend Zeit für die Fehlerbehebung, bevor Details öffentlich gemacht werden.
| Version | Unterstützt | Sicherheits-Updates & SLA |
|---|---|---|
| 0.8.x | ✅ Ja | Aktive Produktionsbasis; 48h-Antwort & 5-Werktage-Triage-SLA |
| < 0.8 | ❌ Nein | Nicht unterstützt; Upgrade erforderlich |
- GitHub Security Advisories (bevorzugt): GitHub Private Vulnerability Reporting
- Direkter Sicherheitskontakt:
security@open-bricks.orgsecurity@dev-bricks.orgsupport@lukasgeiger.comlukas@open-bricks.org
If you find a security vulnerability, please report it responsibly:
- Do not open a public issue
- Use GitHub Private Vulnerability Reporting (
Security→Advisories→New) - Include a description, reproduction steps, and potential impact
If private vulnerability reporting is not enabled yet, contact the maintainers through GitHub and do not publish details in a public issue.
This tool performs security-relevant local operations:
- File system: reads/writes the local SQLite log database, backups, configuration and logs
- Processes: targeted termination of hung Codex desktop processes (process tree). The node-based Codex CLI is never a termination target; broad read-only detection still blocks thread-store mutation while either Desktop or CLI activity is present.
- Windows AppX/Store: register/reset of the Codex Store package (elevated), opening the Store product page
- Normal runtime is local-only: no telemetry, cloud sync, background uploads,
or external API calls (opening the Microsoft Store page is only a local OS
action). The separate
store-materials --live-pagescommand is an explicit manual release preflight; only that opt-in path requests configured Store URLs over HTTPS and returns its own warning/error result. It is never called by the tray, watcher, maintenance loop, or default CLI commands.
- Receipt Acknowledgment (Response SLA): We commit to acknowledging receipt of security reports within 48 hours.
- Triage & Assessment: An initial technical triage and risk assessment will be provided within 5 business days (5 Werktagen).
- Disclosure: Critical issues are prioritized. Please allow reasonable time for remediation before public disclosure.
| Version | Supported | Security Updates & SLA |
|---|---|---|
| 0.8.x | ✅ Yes | Active release; 48h response & 5-business-day triage SLA |
| < 0.8 | ❌ No | Unsupported legacy release; upgrade required |
- GitHub Security Advisories (Preferred): GitHub Private Vulnerability Reporting
- Direct Maintainer Contact:
security@open-bricks.orgsecurity@dev-bricks.orgsupport@lukasgeiger.comlukas@open-bricks.org