Please report vulnerabilities privately through GitHub Security Advisories. Do not open a public issue.
Vulnerabilities in Wasmtime itself (rather than in these Ruby bindings) should be reported to the Wasmtime project.
wasmtime-rb follows Wasmtime's release support policy.
Security fixes are released for:
- The latest release.
- The previous release.
- Wasmtime LTS lines (versions divisible by 12) for as long as Wasmtime
supports them, if
wasmtime-rbpublished a release for that line.
| Version | Supported |
|---|---|
| 49.x | Yes (latest) |
| 48.x | Yes (previous, LTS) |
| 36.x | Yes (LTS) |
| Others | No |
Fixes are developed privately and released on the same day for every affected
supported version, as patch releases from main or from a release-<major>
branch (see Releasing). The advisory is published
once the patched gems are available on RubyGems. Maintainers follow the
vulnerability runbook.
A security release may bump only the patch version, so the gem version can differ from the Wasmtime version it bundles; see Versioning.