Skip to content

Security: nimbalyst/nimbalyst-electronics

SECURITY.md

Security policy

Supported versions

Security fixes are applied to the latest released minor version. The current supported line is 0.2.x.

Reporting a vulnerability

Please use GitHub private vulnerability reporting. Do not open a public issue for a suspected vulnerability or include credentials, private circuit data, local filesystem contents, or provider tokens in a report.

Include the affected Electronics Studio and Nimbalyst versions, operating system, reproduction steps, and impact. We will acknowledge the report, assess the affected surface, and coordinate a fix and disclosure through the private advisory.

Security boundaries

Electronics Studio processes user-authored TSX, Circuit JSON, firmware, and export paths. Treat untrusted project files as untrusted input. Agent actions remain subject to explicit UI approval and the capability limits documented in the README and tool reference. Optional coding-agent providers and supplier services may use the network under their own configuration and policies.

There aren't any published security advisories