| Version | Supported |
|---|---|
| 1.0.x | Yes |
| < 1.0 | No |
Email security reports to the repository owner via GitHub private vulnerability reporting, or open a private security advisory on zowskyy/frontier-syntax.
Please include:
- Description and impact
- Steps to reproduce
- Affected version / commit SHA
- Suggested fix (optional)
We aim to acknowledge reports within 7 days. Critical issues affecting WASM sandbox escape or agent code execution will be prioritized.
In scope:
src/wasm_codegen.rs— incorrect codegen or silent wrong resultsfrontier_agent.py/ agent scripts — unsafe execution or injection.cursor/install.sh— supply-chain or arbitrary code execution
Out of scope:
- Third-party dependencies (report upstream)
- Stubs marked
NOT VERIFIEDinPROJECT_BLUEPRINT.mdPhase 4
Coordinated disclosure preferred. We will credit reporters in release notes unless anonymity is requested.