Security fixes and vulnerabilities are actively monitored and supported for the following versions of Alya:
| Version | Supported |
|---|---|
| 0.0.x | ✅ |
The Alya team takes security bugs seriously. If you discover a vulnerability or security issue in the compiler or runtime:
- Do not create a public GitHub issue.
- Please disclose the vulnerability responsibly through GitHub Security Advisories.
- If GitHub Advisories are not accessible, email details to taiizor@vegalya.com.
To help us triage and fix the vulnerability as fast as possible, please provide:
- A description of the issue and potential impact (e.g. buffer overflow, memory unsafety in runtime assembly, arbitrary execution).
- A minimal reproducible example (
.alyafile). - The exact compiler flags and target architecture/OS.
- Any suggestions or fixes if you have them.
- Acknowledgment: Within 48 hours.
- Assessment & Triage: Within 5 business days.
- Fix & Disclosure: We will work with you to release a patch and publish a credit in the release notes.