Security fixes target the latest CodeXtock release. Before reporting an issue, reproduce it with the newest published version when that can be done safely.
Please use GitHub private vulnerability reporting for vulnerabilities that could expose local data, execute code unexpectedly, alter Codex configuration outside CodeXtock's handler, bypass an explicit confirmation, or consume a Reset Credit incorrectly.
Include:
- the CodeXtock version and Windows version
- the Codex version and whether it came from the CLI or desktop app
- clear reproduction steps and the expected impact
- a minimal proof of concept when appropriate
- logs only after removing personal or account information
Do not include access tokens, auth.json, prompts, responses, tool arguments, proxy credentials, or unredacted Hook payloads. If private vulnerability reporting is unavailable, open a public issue with only non-sensitive symptoms and ask the maintainer for a private contact channel.
CodeXtock is a per-user desktop application. It starts a local Codex app-server, installs a current-user Codex Hook handler when requested, and can create current-user startup and scheduled-wake entries. Auto-reset can change Codex quota state only when explicitly enabled. These behaviors are documented in Privacy and local data.
Unsigned community binaries may trigger Microsoft Defender SmartScreen. Verify release SHA-256 files before installation. A checksum proves file integrity relative to the published checksum; it is not a substitute for Authenticode signing or malware scanning.
Crashes, visual defects, stale quota data, and feature requests that contain no sensitive information can be filed in GitHub Issues. Describe what happened without attaching account data or private session content.