Security fixes are provided for the latest published release. Older releases may be unsupported once a fix is available.
Do not disclose a suspected vulnerability in an issue, discussion, pull request, or other public channel.
GitHub private vulnerability reporting is not currently enabled. Send suspected vulnerabilities confidentially to info@rsitech.ai with “Codebase Combiner security” in the subject. Do not place vulnerability details in a public issue. Omit credentials, private source code, and unrelated personal data; include only the minimum reproduction information needed for investigation.
RSI Tech will acknowledge the report, investigate it, and coordinate remediation and disclosure with the reporter. Timing depends on severity and the complexity of a safe fix.
An artifact is official only when it is attached to a GitHub Release, signed with Apple Developer ID, notarized by Apple, and accompanied by a matching SHA-256 checksum. Signing certificates, notarization credentials, and private keys are never repository contents.