The canonical online trust center is https://pliegocss.dev/security/. This file is the repository-local authority and is kept aligned with that public page.
Before the first stable release, security fixes target the latest prerelease and the default branch.
| Version | Supported |
|---|---|
0.1.0-rc.2 |
Yes |
0.1.0-rc.1 |
No |
| Earlier snapshots | No |
Do not open a public issue. Use GitHub private vulnerability reporting or email
hello@pliegocss.dev with subject SECURITY: short description. Include the
affected version or commit, crate or command, minimal reproduction, impact,
prerequisites, and any known mitigation. Do not include unrelated credentials,
personal data, or proprietary source.
We aim to acknowledge a complete report within three business days and provide an initial assessment within seven business days. These are response goals, not a service-level agreement. Disclosure timing is coordinated after a fix is available.
Security-sensitive surfaces include source discovery, parsers, the compiler, the LSP, migration and repair operations, publication locks, manifests, receipts, browser validation, build scripts, and generated artifacts.
Good-faith research must avoid unauthorized access, privacy violations, data destruction, and service degradation. This policy does not authorize testing a system you do not own or have permission to test.
CI enforces cargo audit, cargo deny, pinned lockfiles, and CodeQL. A clean
advisory report is evidence about known
disclosures only; it is not proof that no vulnerability exists.