Email security@developerz.ai [TBD: ops to confirm]. Do not open public issues for security reports.
Include: affected version, reproduction steps, impact assessment, suggested fix (optional).
Latest minor of each released major/minor line receives security fixes.
| Version | Supported |
|---|---|
| latest minor of each released line | yes |
| older patch releases | no |
90-day window from acknowledgement to public disclosure. We will:
- Acknowledge receipt within 72 hours.
- Validate and assign severity (CVSS v3.1).
- Develop fix, coordinate release.
- Credit reporter in advisory (opt-out available).
TBD — fingerprint will be published here once ops provisions the key.
In scope: engine crates, scripting sandbox, asset pipeline, networking transports, agent API, editor.
Out of scope: third-party plugins, user game code, deployment infrastructure not owned by Nexus.