Skip to content

Security: Pybsama/CodexQuotaMonitor

Security

SECURITY.md

Security Policy

Supported Versions

Only the 0.1.x source line is currently maintained. The repository does not provide a signed and notarized end-user release. Development apps built from source are not supported distribution artifacts.

Version Security updates
0.1.x Supported
Earlier versions Not supported

Report a Vulnerability

Use this repository's GitHub Security Advisories to report a vulnerability privately: open Security → Advisories → Report a vulnerability. Do not create a public Issue for an undisclosed security problem, and do not send the report by email.

Include the affected commit, reproduction conditions, expected result, and observed result. Use synthetic data, and remove user names, host names, absolute paths, and signing identities. Do not attach:

  • tokens, cookies, Authorization headers, or a complete auth.json;
  • state.json, Keychain exports, or real account IDs;
  • screenshots with real quotas, account markers, or notification content;
  • unsanitized logs, crash reports, or build artifacts.

If a data shape is essential, reproduce it with obviously fictional values and a temporary directory. A maintainer may request more information but will not request real credentials.

Scope

This policy covers Codex Quota source and the development build scripts supplied by the repository. User-selected Codex executables, Codex services, OpenAI accounts, and the GitHub platform are outside this project's maintenance scope.

Codex Quota launches the selected Codex subprocess as the current user. File confirmation proves only that the current file matches a saved trust receipt. It does not prove publisher identity, official origin, or absolute safety. See Privacy and Data Flow and Codex Compatibility.

Disclosure and Remediation

Keep the report private until a maintainer confirms the remediation and disclosure plan. After a fix is complete, a maintainer may publish details in the Security Advisory. The project does not promise a fixed response time; progress is recorded in the corresponding Advisory.

There aren't any published security advisories