Security fixes are provided for the latest released version.
Please report vulnerabilities privately through GitHub Security Advisories for this repository. Do not include private source code, credentials, or local index databases in a public issue.
- MCP installation is opt-in and delegated to the public DeusData/codebase-memory-mcp installer.
- Remote plugin installation requires an explicit SHA-256 checksum.
- Release installers verify cbm-projects archives against the release
checksums.txtfile. - Process plugins run with the current user's operating-system permissions. Manifest permissions are disclosures, not a sandbox.
- Project paths and graph indexes remain local unless another explicitly installed plugin sends them elsewhere.