Please report security issues privately, through GitHub's private vulnerability reporting, not in public issues. We will acknowledge the report, investigate, and coordinate a fix and disclosure with you.
In scope: the Pi-Bolt runtime and engine changes (patches/), the release executables, and the scripts and installer in this
repository. Vulnerabilities in Pi itself belong to Pi. Vulnerabilities in upstream Bun
or JavaScriptCore that Pi-Bolt does not change belong to their projects.
Every release publishes SHA256SUMS. The installer verifies each download against it; check manual downloads with:
sha256sum -c --ignore-missing SHA256SUMSPi extensions run inside the Pi process with your permissions, whether they are loaded at run time or compiled in. Only use plugins from sources you trust.