If you discover a security vulnerability within opencodev2-slim, please send an email to serkanalgur via GitHub. All security vulnerabilities will be promptly addressed.
- Dependencies are regularly updated
- No sensitive data is stored in the plugin
- Session data is stored locally only
- No external network requests are made (except to OpenCode API)
When using this plugin:
- Keep your OpenCode installation updated
- Review the plugin configuration regularly
- Report any suspicious behavior immediately
This security policy applies to:
- The main plugin package
- The TUI components
- The configuration system
We appreciate the security research community and responsible disclosure of vulnerabilities.