If you discover a security vulnerability in Transitrix Studio, please report it privately by emailing security@transitrix.com with:
- A description of the vulnerability
- Steps to reproduce it (if possible)
- The affected versions
- Any suggested mitigation or fix
Do not open a public GitHub issue for security vulnerabilities. We will acknowledge receipt within 48 hours and provide a timeline for resolution.
Security updates are provided for:
| Version | Support Status |
|---|---|
| 3.5.x | Current release |
| 3.4.x | Maintenance fixes |
| < 3.4 | End of life |
We recommend keeping your extension updated to the latest version to receive security patches promptly.
Transitrix Studio has undergone formal security audits, including provenance verification of published artifacts. Our audit process includes:
- Source code review
- Dependency inventory (SBOM)
- Build provenance attestation
- Binary integrity verification
Published audit findings are available in the security audit record.
Each release is attested using GitHub build provenance. To verify the provenance of a released .vsix file:
gh attestation verify --owner transitrix transitrix-studio-X.Y.Z.vsixReplace X.Y.Z with the version number. The command confirms that the artifact was built by our CI pipeline and has not been tampered with.
Detailed attestation verification instructions are included in each release's notes.
Transitrix Studio:
- Declares all production dependencies in
package.json - Pins dependency versions to ensure reproducible builds
- Receives automated dependency security updates via Dependabot
- Does not include proprietary or closed-source components
The complete component inventory for each release is available as a CycloneDX SBOM (Software Bill of Materials) attached to the release.
Each published release includes a CycloneDX-format SBOM (sbom.xml) listing all components and their versions as shipped in the extension package. This allows you to:
- Audit what is included in the release
- Cross-reference against known vulnerabilities
- Verify component versions against your compliance requirements
The SBOM is generated during the build process from the actual packaged extension, not from source declarations.
- All commits are signed
- Pull requests require review before merge
- CI/CD pipeline verifies code quality and tests
- Build artifacts are attested and signed
- Archive hashes are reproducible and published
For non-security questions about Transitrix Studio, please open an issue on GitHub or visit transitrix.com.