This policy applies to all parts of the Robot Framework Electron & VS Code project: the Python packages
robotframework-electronandrobotframework-vscode, the documentation site, and the example project.
Please do not open public issues for security problems.
Primary: Use GitHub's Private Vulnerability Reporting on this repository:
- Go to the repository's Security tab → Report a vulnerability
- Creates a private, secure thread with the maintainers
- Automatically tracks communication and resolution
Alternative: Email support@robotcode.io
- This address is actively monitored by the maintainers
- PGP encryption available upon request
- If this address is unavailable, contact the maintainer via the email listed in the latest release notes
When reporting, please include:
- Component: Affected package and version (
robotframework-electron,robotframework-vscode), the documentation site, or the example project - Description: Clear description of the vulnerability and attack vector
- Impact: Potential impact and your severity assessment (CVSS score welcome)
- Reproduction: Steps to reproduce, proof of concept, or minimal repro project
- Environment: OS, display setup, Python, Robot Framework and Browser library versions, and the Electron application or VS Code version under test
- Mitigations: Any known workarounds or temporary fixes
We also accept supply-chain reports (malicious dependencies, typosquats, unsafe defaults) affecting the project.
- Triage acknowledgement: within 3 business days
- Initial assessment: within 7 days we'll confirm scope, assign severity (CVSS score), and provide timeline for resolution
- Regular updates: every 14 days on progress for confirmed vulnerabilities
- Fix target: within 90 days for high/critical issues, next regular release for medium/low severity issues
For critical vulnerabilities (CVSS 9.0+, active exploitation, or RCE):
- Acknowledgement: within 24 hours
- Assessment: within 48 hours
- Emergency release: within 14 days when feasible
- Standard disclosure timeline: 90 days after fix release, or by mutual agreement
- We'll coordinate with you on public disclosure timing
- Please do not disclose details publicly until we publish an advisory/release with a fix
- We may request extended timeline for complex fixes requiring upstream coordination
We use CVSS v4.0 (v3.1 also accepted) with the following guidelines:
| Severity | CVSS Score | Examples |
|---|---|---|
| Critical | 9.0-10.0 | Remote Code Execution, Privilege Escalation without user interaction |
| High | 7.0-8.9 | RCE requiring user interaction, Authentication bypass, Sensitive data exposure |
| Medium | 4.0-6.9 | Local privilege escalation, Limited information disclosure, DoS |
| Low | 0.1-3.9 | Minor information leakage, UI spoofing |
- The
robotframework-electronandrobotframework-vscodepackages - How they download VS Code, install extensions, and start Electron applications and VS Code instances
- Documentation site content and example code that could cause vulnerabilities when followed
- Supply chain issues (malicious dependencies, typosquatting)
- Configuration defaults that create security risks
- Browser library, Playwright, Electron, VS Code and Robot Framework themselves (report to the respective project)
- Extensions and Electron applications under test, and extensions installed into the tested VS Code
- Third-party dependencies unless there's a vulnerable usage pattern within this project
- Issues requiring unrealistic attack scenarios (e.g., running arbitrary untrusted Robot tests in production without sandboxing)
- Social engineering attacks against project maintainers
- Physical access scenarios
Project Versions:
- Latest release of both packages receives full security support
- Older versions are out of security support while the project is at version 0.x
Dependencies & Requirements:
- Minimum requirements: Python 3.10+ and the Browser library version declared by the packages
- Dependency security: Python, Robot Framework, the Browser library, Playwright, Electron and VS Code have their own security policies and support lifecycles
- Out of scope: Security issues in these dependencies should be reported to their respective projects
- Compatibility: We may drop support for end-of-life Python, Robot Framework, Electron or VS Code versions without prior notice
- We assess severity using CVSS v4.0 (Base score + Threat/Environmental when applicable)
- CVEs will be requested for vulnerabilities with CVSS ≥ 7.0 or significant user impact
- GitHub Security Advisories will be published describing impact, affected versions, and remediation
- All advisories include the CVSS vector and detailed mitigation steps
Unless you request otherwise, we will:
- Credit reporters by name or handle in security advisories
- Mention contributors in release notes
While we don't offer monetary rewards, we provide:
- Public recognition and attribution
- Direct communication channel with maintainers for future research
- Conference speaking opportunity referrals when appropriate
✅ Encouraged:
- Testing in isolated environments
- Responsible proof-of-concept development
- Coordinating with our team before public research
❌ Prohibited:
- Data destruction, exfiltration, or privacy violations
- Testing against production systems of other users
- Spam, DoS, or aggressive automated scanning
- Social engineering attempts against maintainers or users
- Application privileges: The libraries start Electron applications and VS Code with the privileges of the test run, and the extension under test runs with them too; run tests as a dedicated user, in a container or virtual machine
- Isolated instances: VS Code instances get their own user data and extensions directories, so tests do not touch your own VS Code, but they still share your file system and network
- Extensions: Install only extensions you trust into the tested VS Code; they come from the Marketplace, or from the gallery of the fork you test
- Versions: Pin the VS Code and Electron versions you test against, and update them deliberately
- Code Review: Treat Robot Framework test suites as code - review before execution
- Sandboxing: Run untrusted tests in containerized or sandboxed environments
- Access Control: Limit file system access for automated test execution
- Keep Python, Robot Framework, the Browser library and these packages up to date
- Subscribe to GitHub security advisories for notifications
- Monitor release notes for security-related changes
This security policy is subject to change. The current version is the one in the repository's default branch.
By participating in our security research program, you agree to:
- Follow responsible disclosure practices
- Comply with applicable laws and regulations
- Respect user privacy and data protection requirements
Thank you for helping keep the project and its users secure!
Last updated: 2026-10-10 Version: 1.0