Security fixes are provided for the latest release line and active bootstrap seed workflow. Older releases may not receive patches.
| Version / Line | Supported |
|---|---|
| Latest stable release | ✅ |
| Active stage1 seed tag | ✅ |
| Older releases | ❌ |
Please do not open public issues for suspected security vulnerabilities.
Report privately by email:
When reporting, include:
- Affected version/tag/commit
- Reproduction steps or proof-of-concept
- Impact assessment (what can be exploited)
- Any suggested mitigation
We will acknowledge receipt as soon as possible and keep you updated through triage, validation, fix, and disclosure.
Our standard process:
- Acknowledge report
- Validate and assess severity
- Prepare and test a fix
- Coordinate disclosure and release notes
- Publish advisory details once users can patch
Given this project's bootstrap model, reports related to compiler trust chain, stage1 seed integrity, release artifact provenance, and workflow tampering are in scope and treated with high priority.