Skip to content

Security: roughstack/execution-runtime

Security

SECURITY.md

Security policy

Report sandbox escapes, protocol injection, resource-limit bypasses, path traversal, cross-submission data exposure, result forgery, or secret leakage through GitHub's private vulnerability reporting. Do not publish exploit details in an issue, discussion, pull request, fixture, or test log.

The SDKs and runner protocol do not provide process isolation. A production deployment must place compilation and execution inside a separately reviewed sandbox with no ambient credentials, no writable host mounts, denied network egress, bounded output, and enforced CPU, memory, process, and wall-clock limits.

Security fixes target the current main branch until versioned releases are published.

There aren't any published security advisories