Do not open a public issue for a suspected vulnerability. Use GitHub Private Vulnerability Reporting for this repository instead:
https://github.com/mywwave/bb-plugin-code-intelligence/security/advisories/new
Before relying on this policy, the maintainer must enable Private Vulnerability Reporting in the repository's GitHub security settings. If it is not yet enabled, do not publish sensitive details; use the maintainer's private GitHub-profile contact method to request a secure reporting channel.
Only the latest commit on main is supported before the project publishes a
stable major release. Reports against older revisions should include evidence
that the issue still reproduces on current main.
The maintainer aims to acknowledge a report within seven calendar days and to share a triage decision or mitigation plan within 30 days. These are targets, not a guarantee of a fix or a disclosure date.