Skip to content

Security: flakeforge/ekspertor

Security

SECURITY.md

English · Oʻzbekcha

Security policy

This is the default policy for FlakeForge repositories. A repository with its own SECURITY.md overrides it.

Reporting a vulnerability

Do not open a public issue, and do not post it in the Telegram group.

Report it privately through GitHub: open the affected repository, go to the Security tab and choose "Report a vulnerability". That creates a private advisory only you and the maintainers can read.

If the repository has advisories turned off, or you would rather not use GitHub, write to contact@flakeforge.com with "security" in the subject.

Include what you found, the steps to reproduce it, and what an attacker could do with it. A proof of concept helps, even a rough one.

What to expect

We aim to acknowledge a report within a few days. While we investigate we will tell you what we find and roughly when a fix should land. Once it is released, the advisory is published with credit to you, unless you ask us not to name you.

Please give us time to ship a fix before writing about it publicly.

Supported versions

Only the latest release on main receives security fixes. We do not backport to older tags.

Out of scope

  • Findings from an automated scanner with no demonstrated impact
  • Missing hardening headers or best practice suggestions with no exploitable consequence
  • Reports about content our tools generate on a user's request, such as a QR code pointing to an unsafe site
  • Third party services we use but do not control

Thank you

Reporting a problem you could have kept to yourself takes effort. We would rather hear it from you than from an incident.

There aren't any published security advisories