Skip to content

Security: johnpapa/vscode-peacock

SECURITY.md

Security Policy

Reporting a Vulnerability

If you discover a security vulnerability in Peacock, please report it responsibly.

Do not open a public issue. Instead, use GitHub's private vulnerability reporting or email johnpapa@gmail.com.

Scope

Peacock is a VS Code extension that modifies workspace color settings. The primary security concerns are:

  • Extension code that could access or modify files beyond VS Code color settings
  • Dependencies with disclosed vulnerabilities (monitor via npm audit)
  • Webpack build output integrity

Supported Versions

Only the latest published version on the VS Code Marketplace receives security updates.

There aren't any published security advisories