DocsCommunitySecurity & Vulnerability Disclosure
Community

Security & Vulnerability Disclosure

Security policy, supported versions, and responsible disclosure process.

Security Policy

NextViper is maintained by Nuratix LLC ([nuratix.com](https://nuratix.com)). We take the security and integrity of our compiler, runtime, package manager, and registry infrastructure seriously.


1

Supported Versions

Security updates are actively provided for the following release branches:

VersionSupportedSecurity Maintenance Status
`1.0.x`YesActive Security Fixes & Patch Releases
`< 1.0.0`NoPre-release development versions (Upgrade to 1.0.x)

2

Reporting a Vulnerability (Responsible Disclosure)

If you discover a security vulnerability in the NextViper compiler, runtime engine, LSP, or official package registry:

  • Do NOT Open a Public Issue: Please do not file public GitHub issues, forum posts, or public pull requests containing zero-day exploit information.
  • Private Security Advisory / Email:
  • Use GitHub's [Private Vulnerability Reporting](https://github.com/nuratix/nextviper/security/advisories/new) feature on the repository.
  • Alternatively, email `security@nuratix.com` with full vulnerability details, reproduction steps, and potential remediation.
  • Response Timelines:
  • Initial Acknowledgement: Within 24–48 hours.
  • Assessment & Triage: Within 5 business days.
  • Patch Release & Advisory: Disclosed cooperatively after fix validation.