Trust / Security
Security policy
Block Engine is a local-first execution engine. Security reports are handled through the public repository with a private channel for vulnerabilities.
Report a vulnerability
Please do not disclose an exploitable vulnerability in a public issue. Use a private GitHub Security Advisory and include the affected version, edition, operating system, minimal reproduction, impact, and sanitized logs.
What to protect
Reports involving process execution, path traversal, state injection, installer behavior, runtime isolation, or secret exposure are especially useful. Do not upload credentials, certificates, private keys, or malicious samples containing real user data.
Release verification
Release artifacts are published through GitHub Releases with a SHA-256 manifest. Verify the checksum before installation and review the release notes.
Machine-readable policy
The public machine-readable policy is available at /.well-known/security.txt.