Only the 0.1.x source line is currently maintained. The repository does not
provide a signed and notarized end-user release. Development apps built from
source are not supported distribution artifacts.
| Version | Security updates |
|---|---|
0.1.x |
Supported |
| Earlier versions | Not supported |
Use this repository's GitHub Security Advisories to report a vulnerability privately: open Security → Advisories → Report a vulnerability. Do not create a public Issue for an undisclosed security problem, and do not send the report by email.
Include the affected commit, reproduction conditions, expected result, and observed result. Use synthetic data, and remove user names, host names, absolute paths, and signing identities. Do not attach:
- tokens, cookies, Authorization headers, or a complete
auth.json; state.json, Keychain exports, or real account IDs;- screenshots with real quotas, account markers, or notification content;
- unsanitized logs, crash reports, or build artifacts.
If a data shape is essential, reproduce it with obviously fictional values and a temporary directory. A maintainer may request more information but will not request real credentials.
This policy covers Codex Quota source and the development build scripts supplied by the repository. User-selected Codex executables, Codex services, OpenAI accounts, and the GitHub platform are outside this project's maintenance scope.
Codex Quota launches the selected Codex subprocess as the current user. File confirmation proves only that the current file matches a saved trust receipt. It does not prove publisher identity, official origin, or absolute safety. See Privacy and Data Flow and Codex Compatibility.
Keep the report private until a maintainer confirms the remediation and disclosure plan. After a fix is complete, a maintainer may publish details in the Security Advisory. The project does not promise a fixed response time; progress is recorded in the corresponding Advisory.