Only the latest published beta receives security fixes during the 0.x design-partner
period. Older prereleases are unsupported.
| Version | Supported |
|---|---|
Latest beta dist-tag |
Yes |
| Earlier prereleases | No |
Use GitHub's private vulnerability reporting. Do not open a public issue, post in Discord, or include real candidate or employer data.
Include:
- the affected version and platform;
- a synthetic proof of concept;
- expected and observed impact;
- suggested mitigations, if known.
The maintainer will acknowledge reports on a best-effort basis, validate impact, coordinate a fix and advisory, and credit reporters who want attribution. No bounty program or response SLA is currently offered.
Inside the Build is local-first and has no hosted service, but it reads sensitive local session files and passes extracted text to a local coding agent. Important unresolved risks, including prompt injection and lack of built-in redaction, are documented in Known limitations. Those disclosed limitations are not themselves security vulnerabilities unless a report demonstrates impact beyond the documented model.