Please do not open a public GitHub issue for security vulnerabilities.
Instead, email contact@getlinea.app with:
- A description of the vulnerability and its potential impact
- Steps to reproduce, or a proof of concept if you have one
- Any relevant logs, screenshots, or affected versions/commits
We aim to acknowledge reports within 3 business days and will follow up with next steps once we've triaged the report. Please give us a reasonable amount of time to investigate and fix an issue before disclosing it publicly.
Linea is early-stage and pre-1.0. There are no stable release branches yet —
only the main branch is maintained, and security fixes land there directly.
This section will be updated once versioned releases exist.
This policy covers the code in this repository. It does not cover vulnerabilities in third-party dependencies (please report those upstream) or issues in Linea's hosted infrastructure that aren't reproducible from this codebase — for hosted-service concerns, use the same contact@getlinea.app address and we'll route it appropriately.