We take the security of this project seriously and appreciate responsible disclosure of vulnerabilities.
Please do not report security vulnerabilities through public GitHub issues, discussions, or pull requests.
Instead, report them privately through GitHub's built-in Security Advisories:
- Go to the Security tab of this repository.
- Click Report a vulnerability.
- Fill in the details using the Privately report a vulnerability form.
This creates a private advisory visible only to you and the maintainers.
Please include as much of the following as you can to help us triage quickly:
- The type of issue and the affected component (e.g., dependency extraction, analysis, rendering).
- The version of the plugin and the IDE (IntelliJ IDEA / Android Studio) you are using.
- Step-by-step instructions to reproduce the issue.
- Proof-of-concept or exploit code, if available.
- The potential impact, including how an attacker might exploit it.
- We will acknowledge your report as soon as we are able to.
- We will investigate and keep you informed of our progress.
- Once the issue is resolved, we will coordinate disclosure and credit you, if you wish.
This policy covers the source code in this repository. Vulnerabilities in third-party dependencies should be reported to the respective upstream projects, though we welcome a heads-up so we can update affected dependencies.