Please report security vulnerabilities via GitHub. Do NOT open a public issue for security vulnerabilities.
We will acknowledge receipt within 48 hours and provide an initial assessment within 7 days.
| Version | Supported |
|---|---|
| latest | Yes |
cargo-denychecks for known advisories in dependenciescargo-auditruns in CI on every PR- No
unsafecode allowed in thetransforms/crate - No network calls or filesystem access in transform functions
- WASM extension runs inside Zed's sandboxed extension host