English · Oʻzbekcha
This is the default policy for FlakeForge repositories. A repository with its own SECURITY.md overrides it.
Do not open a public issue, and do not post it in the Telegram group.
Report it privately through GitHub: open the affected repository, go to the Security tab and choose "Report a vulnerability". That creates a private advisory only you and the maintainers can read.
If the repository has advisories turned off, or you would rather not use GitHub, write to contact@flakeforge.com with "security" in the subject.
Include what you found, the steps to reproduce it, and what an attacker could do with it. A proof of concept helps, even a rough one.
We aim to acknowledge a report within a few days. While we investigate we will tell you what we find and roughly when a fix should land. Once it is released, the advisory is published with credit to you, unless you ask us not to name you.
Please give us time to ship a fix before writing about it publicly.
Only the latest release on main receives security fixes. We do not backport to older tags.
- Findings from an automated scanner with no demonstrated impact
- Missing hardening headers or best practice suggestions with no exploitable consequence
- Reports about content our tools generate on a user's request, such as a QR code pointing to an unsafe site
- Third party services we use but do not control
Reporting a problem you could have kept to yourself takes effort. We would rather hear it from you than from an incident.