Skip to content

Security: Nexa-Language/Nexa

SECURITY.md

Security Policy

Supported Versions

We are committed to providing security updates for the following versions of Nexa. We recommend all users to stay on the latest stable release.

Version Supported
1.3.x
1.0.x
< 1.0

Reporting a Vulnerability

Please do not report security vulnerabilities through public GitHub issues.

If you discover a potential security vulnerability in Nexa, please help us protect our users by reporting it privately.

Where to report

Please send an email to [INSERT_SECURITY_EMAIL].

What to expect from us

  • Acknowledgment: You will receive an acknowledgment of your report within 48 hours.
  • Investigation: Our team will investigate the issue and may contact you for further details or reproduction steps.
  • Resolution: Once a vulnerability is confirmed, we will work on a fix. We will keep you updated on the progress.
  • Public Disclosure: After the fix is released, we will coordinate a public disclosure (typically via a Security Advisory or Release Note) and, if you wish, credit you for the discovery.

Please include the following in your report:

  • A brief description of the vulnerability.
  • Steps to reproduce the issue (proof-of-concept code is highly appreciated).
  • Potential impact (e.g., can it lead to remote code execution? data leakage?).
  • Any suggestions for remediation.

Thank you for helping us keep the Nexa community safe!

There aren't any published security advisories