Che4z follows the Eclipse Vulnerability Reporting Policy. Vulnerabilities are tracked by the Eclipse security team, in cooperation with the Che4z project lead. Fixing vulnerabilities is taken care of by the Che4z project committers, with assistance and guidance of the security team.
Che4z supports security updates only for the latest version.
We recommend that in case of suspected vulnerabilities you do not use the Che4z public issue tracker, but instead contact the Eclipse Security Team directly via [email protected].