Nexus Language

Security

Report responsibly

Please { not open public issues for security-sensitive reports. Prefer GitHub private vulnerability reporting on theworker02/nex-lang when available.

Supported versions

Fixes land on the current main branch. TypeScript toolchain and Nex LSP are supported; the legacy Go CLI is best-effort. There is no LTS line yet.

What to include

  • Affected component (CLI, extension, builtins, site, …)
  • Version or commit hash
  • Steps to reproduce and impact

Expectations

Acknowledgement within about 7 days on a best-effort basis. This is a small open-source project maintained by theworker02 / nex-lang project maintainers.

Scope note

Treat untrusted .nex programs like untrusted scripts — host builtins can perform real I/O. Full policy: SECURITY.md in the repository.