Core documentation

Security

Please report security issues privately to the-open-engine maintainers. Do not open public issues for secrets, credential exposure, sandbox escapes, or supply-chain vulnerabilities.

Include:

§Supported Versions

The replacement engine receives security fixes in the following release line:

VersionSupported
0.3.xyes
legacy releases and earlier snapshotsno

§Scope

Security-sensitive areas include Git and ASP input capture, bounded parsers, native-provider subprocess execution, installer path and ownership checks, npm archive verification, and release automation.