Security
Report responsibly
Please { not open public issues for security-sensitive reports. Prefer GitHub private vulnerability reporting on theworker02/nex-lang when available.
Supported versions
Fixes land on the current main branch. TypeScript toolchain and Nex LSP are supported; the legacy Go CLI is best-effort. There is no LTS line yet.
What to include
- Affected component (CLI, extension, builtins, site, …)
- Version or commit hash
- Steps to reproduce and impact
Expectations
Acknowledgement within about 7 days on a best-effort basis. This is a small open-source project maintained by theworker02 / nex-lang project maintainers.
Scope note
Treat untrusted .nex programs like untrusted scripts — host builtins can perform real I/O. Full policy: SECURITY.md in the repository.