| Version | Supported |
|---|---|
| 0.3.x | ✅ |
| 0.2.x | ✅ |
| < 0.2 | ❌ |
DO NOT open a public GitHub issue for security vulnerabilities.
Instead, please:
- Email: See
.well-known/security.txtfor contact information - Expected Response: Within 48 hours
- Disclosure Timeline: 90-day coordinated disclosure
- Memory Safety: WASM (Rust) provides memory safety guarantees
- Type Safety: ReScript compile-time types
- Sandboxing: WASM runs in isolated linear memory
- Permissions: Deno explicit permissions (
--allow-read,--allow-write) - Data Privacy: Local-first, no network calls, no telemetry
- Offline-First: Works completely air-gapped
- Threat Model: See
THREAT_MODEL.md - Security Contact: See
.well-known/security.txt
If a CVE is assigned:
- Acknowledgment within 24 hours
- Patch development within 7-14 days
- Security update release
- Advisory on GitHub Security
- CHANGELOG.md update