Skip to content

Security: pilotworks/scriptgo

Security

SECURITY.md

Security Policy

Supported Versions

Security updates are provided for the following versions:

Version Supported
0.1.x
< 0.1

Reporting a Vulnerability

The ScriptGo team takes the security of our compiler, runtime, and emitted executables seriously.

If you discover a security vulnerability, please do NOT open a public issue. Instead, follow these steps:

  1. Email Us: Send details to security@scriptgo.dev (or open a Private Security Advisory via GitHub).
  2. Provide Details:
    • Description of the vulnerability.
    • Minimal TypeScript reproduction code.
    • Target architecture and OS where the issue reproduces.
    • Any potential impact on memory safety or arbitrary execution.
  3. Response Time: We will acknowledge receipt of your report within 48 hours and provide a timeline for triage and resolution.
  4. Coordinated Disclosure: We adhere to coordinated vulnerability disclosure and will credit researchers in our release notes.

There aren't any published security advisories