Sulfur is currently under active development and does not yet have stable release versions.
Security issues affecting the current development version are welcome.
Please do not report security vulnerabilities through public GitHub Issues.
If you believe you have found a security vulnerability in Sulfur, please contact the project maintainers privately with:
- A description of the vulnerability
- Steps to reproduce it
- A minimal example, if applicable
- The expected and actual behavior
- Any relevant compiler output
Please allow reasonable time for the issue to be investigated before publicly disclosing it.
Security reports may include issues involving:
- The compiler
- Generated code
- Memory safety
- Incorrect semantic validation
- Unexpected compiler behavior
- Build or tooling security issues
Issues that are purely language-design disagreements are not considered security vulnerabilities.