# Security Policy

Pi extensions execute with the user's system permissions. Review the source before installation.

## Supported versions

| Version | Supported |
| --- | --- |
| 0.1.x | Yes |

## Reporting a vulnerability

Please report suspected vulnerabilities privately through GitHub's security-advisory feature for `Naees/pi-loops`. Do not open a public issue for an unpatched vulnerability.

Include reproduction steps, affected platforms, expected impact, and any suggested mitigation. Reports will be acknowledged as soon as practical.

## Automated checks

Release automation validates production dependency advisories, reviewed SPDX licenses, a CycloneDX production-dependency SBOM, high-confidence tracked-secret patterns, immutable GitHub Action references, package contents, and static analysis. These checks supplement rather than replace manual review of process, filesystem, Git, event, evaluator, and deletion boundaries.

## Release requirements

A public release is blocked by unresolved critical or high-severity findings, an unproven child-process cleanup guarantee, unintended files in the npm tarball, an unclean release tree, failure of the authenticated macOS runtime gate, or failure of native Linux or Windows qualification.
