Skip to content

Security: LH-03/codex-cli-home-switcher

Security

SECURITY.md

Security policy

Sensitive data

Do not include API keys, access tokens, auth.json, real provider configuration, session history, logs, or a copied Codex home in an issue, pull request, test fixture, or release asset.

The switcher needs only profile names and absolute home paths. It deliberately does not parse the contents of a Codex home.

Reporting a vulnerability

Use GitHub's private security-advisory flow for this repository when available. Do not open a public issue containing credentials or an exploitable proof that exposes another person's data.

If a credential was posted publicly, revoke it with its provider immediately; deleting the post is not enough.

There aren't any published security advisories