Skip to content

Security: cambra-dev/cambra

Security

SECURITY.md

Security Policy

Cambra is a research preview. It has not been hardened for production use, and there is no bounty program.

Reporting a vulnerability

Please don't open a public issue for a security problem. Instead, use GitHub's private vulnerability reporting: Report a vulnerability (also reachable via this repo's Security tab). If you can't use GitHub for this, email public@cambra.dev. We can't promise a fix timeline, but we do read every report and will acknowledge it.

This applies to the language, compiler, and interpreter in this repository. If your report concerns other Cambra services, email public@cambra.dev and we'll route it appropriately.

There aren't any published security advisories