Security updates are provided for the following versions:
| Version | Supported |
|---|---|
| 0.1.x | ✅ |
| < 0.1 | ❌ |
The ScriptGo team takes the security of our compiler, runtime, and emitted executables seriously.
If you discover a security vulnerability, please do NOT open a public issue. Instead, follow these steps:
- Email Us: Send details to
security@scriptgo.dev(or open a Private Security Advisory via GitHub). - Provide Details:
- Description of the vulnerability.
- Minimal TypeScript reproduction code.
- Target architecture and OS where the issue reproduces.
- Any potential impact on memory safety or arbitrary execution.
- Response Time: We will acknowledge receipt of your report within 48 hours and provide a timeline for triage and resolution.
- Coordinated Disclosure: We adhere to coordinated vulnerability disclosure and will credit researchers in our release notes.