ERDL™ is a deterministic rule evaluation language. The evaluation kernel is designed to be safe by construction: no code injection paths, a bounded resource model (spec §7.2 E4), ReDoS-protected regex (§7.3(d)), and pure function semantics (E1).
If you discover a security vulnerability, please do not open a public issue. Instead, report it privately to:
Please include:
We will acknowledge receipt, investigate, and coordinate a fix and disclosure with you.
| Version | Supported |
|---|---|
| 2.0.x | Yes |
| < 2.0 | No |
The ERDL evaluation kernel maintains the following security properties (see the spec §7):
If you believe any of these properties is violated, please report it.