Update Coder CVE Malicious Packages Served from Unauthorized Registry Server
Coder Logo

Trust Center

Start your security review
View & download sensitive information
Ask for information
ControlK

Trust Center Updates

Update Coder CVE Malicious Packages Served from Unauthorized Registry Server

Incidents

On August 31, an unauthorized party used a compromised Cloudflare API key to change the DNS records for registry.coder.com and direct it to infrastructure they controlled. Terraform module versions served from that infrastructure had been modified to steal cloud credentials. Following discovery, we removed the malicious DNS changes, notified customers, and published the details in advisory GHSA-vx42-ghc9-gw65.

We have now engaged an independent incident response firm to review how we handled the incident, including how quickly we detected it, whether our containment was adequate, if there are any remaining issues to be remediated. We will share a summary of their findings and the changes we make as a result, and we will commit to a date for providing this information once their work is far enough along to support one.

The trust our customers place in Coder is our most valuable asset. We remain committed to protecting it through the security of our platform and through transparency with you about how we operate.

Coder is starting to update customers via SafeBase for company updates.

General

Coder will use this Trust Center to update customers on any subprocessor, vulnerability, or incident information going forward.

Welcome to Coder's Trust Center. Our commitment to data privacy and security is embedded in every part of our business. Use this Coder Trust Center to learn about our security posture and request access to our security documentation.

Documents

Featured Documents

SELF-ASSESSMENTSCAIQ Lite

Data Security

We follow industry best practices for data security. We are happy to provide more details about our data security practices upon request.

AI

We take the usage of AI seriously in our organization and work to ensure security and reliability of the AI.

Legal

We take legal matters seriously and we always engage our legal counsel to review all commercial activities. Please contact us if you have any questions.

Data Privacy

Privacy of customer data is top of mind. We follow industry best practices and follow all applicable privacy regulations.

Access Control

Access is tightly monitored and controlled at our company. We are happy to provide more details about our access control practices upon request.

Infrastructure

We take great care to work with best-in-class infrastructure providers that provide secure computing and storage. We are happy to provide more details about our infrastructure upon request.

Network Security

We protect our corporate network against external & internal threats.

Incident Response

We have a dedicated team that responds to security incidents. We are happy to provide more details about our incident response practices upon request.

Risk Management

We have a dedicated team that manages security risks. We are happy to provide more details about our risk management practices upon request.

Asset Management

We have strict asset management policies in place to ensure that all assets are accounted for and secure.

Change Management

We have a change and configuration management process in place to ensure that changes are properly reviewed and approved.

Continuous Monitoring

We continuously monitor our systems for security threats and vulnerabilities. We are happy to provide more details about our continuous monitoring practices upon request.

Built onSafeBase by Drata Logo