If you discover a security vulnerability in the MIRR compiler, the WASM bindings, or the interactive paper infrastructure, please report it responsibly.
- Do NOT open a public GitHub issue for security vulnerabilities.
- Email: brandonfromph@users.noreply.github.com
- Include: description, reproduction steps, affected version, severity assessment.
- Compiler bugs that produce incorrect hardware (wrong RTL output)
- WASM sandbox escapes
- Service Worker cache poisoning
- XSS or injection via the interactive paper
- Dependencies with known CVEs
- Bugs in example
.mirrfiles - Cosmetic issues in documentation
- Feature requests
- Acknowledgment: within 48 hours
- Initial assessment: within 7 days
- Fix or mitigation: best effort, disclosed after fix lands
| Version | Supported |
|---|---|
| 0.3.x | Yes |
| < 0.3 | No |
We follow coordinated disclosure. Security fixes are committed to main
with a CVE identifier when applicable. No bounty program exists at this time.