Security fixes are provided for the current 1.x release line.
Use GitHub's private vulnerability reporting for the CoderDrift repository. Do not open a public issue for a vulnerability that could expose local annotation data, identifiers, paths, or report content. Include the affected version, a minimal synthetic reproduction, and the expected impact. Do not attach third-party raw annotation data.
CoderDrift runs locally and sends no telemetry. Reports can still contain pseudonymous sequence-level results supplied by the user, so deployment and file-access controls remain the user's responsibility.