| Version | Supported |
|---|---|
| 0.1.x | ✅ |
| < 0.1 | ❌ |
We actively support the latest 0.1.x release. Security fixes are backported when feasible.
Please report security vulnerabilities privately via GitHub Security Advisories. If advisories are unavailable (e.g. in a fork), email s.wielgosz@noxgle.com with "[SECURITY] " in the subject. Do not open a public issue for security-sensitive bugs.
Include:
- A description of the vulnerability and its impact.
- Steps to reproduce (code, commands, or configuration).
- Your assessment of severity (if any).
We aim to acknowledge reports within 48 hours and provide a fix or mitigation plan within 30 days for confirmed vulnerabilities.
auth.json— API keys and OAuth tokens; written with mode0600on POSIX.settings.json/models.json— configuration; written atomically.- Session JSONL files (
sessions/*.jsonl) — conversation history; written atomically. ONE_CODING_AGENT_DIRcan override the default~/.config/one.
Text configuration files and session JSONL are written through atomic
tempfile + os.replace to prevent truncation on interruption, and new
directories are created with mode 0700. The blob store for image attachments
uses its own dedicated 0600/0700 handling (content-addressed blobs with
exclusive temp files and fsync).
- Project extensions (
.one/extensions/*.py) are imported and executed at session startup. They run with the same permissions asone— not sandboxed. - MCP server commands (from
.one/settings.json) are spawned as child processes. They run with the same permissions asone— not sandboxed. - Bash tool executes shell commands in the project working directory.
- File tools (read/write/edit/grep/find/ls) operate on the filesystem.
- Cooperation mode is an approval gate only, not a sandbox. Tools still execute with full permissions.
Provider API keys and OAuth tokens are sent to the respective provider
endpoints over HTTPS. one does not proxy or log this traffic. Token
redaction is applied to error messages and RPC responses.
- Anthropic and ChatGPT/Codex subscription logins are supported production features, but they use reverse-engineered OAuth flows. These endpoints are not part of any public API and are externally controlled by the respective providers.
- They may change without notice. Third-party use of subscription credentials against these backends is at the user's own risk and may violate the provider's Terms of Service.
- Tokens are stored in
auth.jsonand automatically refreshed before expiry.
API keys can be supplied via environment variables (OPENAI_API_KEY,
ANTHROPIC_API_KEY, etc.) as an alternative to auth.json. Environment
variables take precedence over stored keys but are not persisted.
- Only run
onein trusted repositories. Useone --no-extensions --no-mcpfor untrusted code. - Keep
auth.jsonprivate. Verify file permissions (stat auth.jsonshould show600). - Use
ONE_CODING_AGENT_DIRto isolate session data when testing. - Pin dependencies in production environments.
- Review extensions before loading untrusted custom packages.
If you need to contact maintainers without using advisories, email s.wielgosz@noxgle.com with "[SECURITY] " in the subject.