FlipDeFlock is a security tool, so it should be held to the standard it audits against.
Please do not open a public issue for a security problem.
Use GitHub's private vulnerability reporting: Security → Report a vulnerability. That opens a private advisory visible only to you and the maintainer.
Expect an acknowledgement within a week. This is a single-maintainer project, so please allow reasonable time for a fix before public disclosure — 90 days is the default, less if an issue is being actively exploited, more if we agree a fix needs longer.
Only the latest release receives fixes. There are no long-term support branches.
- The Flipper app (
.fap) — memory safety, crashes, and anything that lets untrusted radio input or SD-card content compromise the device. signatures.jsonparsing (helpers/sig_db.c) — this reads a user-supplied file from the SD card and is the app's primary untrusted-input surface. Findings here are especially welcome.- Report writers (
helpers/recon_report.c,helpers/report_escape.c) — a hostile SSID or BLE device name must not be able to break out of a CSV column, inject KML elements, or otherwise corrupt a report. - The ESP32 companion firmware (
esp32_companion/) and the UART wire protocol. - The in-app flasher plugin (
plugins/flasher/).
- Missed detections and false positives. These are correctness bugs, not vulnerabilities — please open a normal issue. Detections are indicators, not proof, by design.
- The absence of network features. FlipDeFlock never transmits and never connects to a network. That is intentional and is a core principle, not an oversight.
- Physical access to an unlocked Flipper.
- Forks, clones, and repackaged builds we do not control. See below.
Official binaries come only from this repository's Releases or from per-push CI artifacts under the Actions tab. A tagged release currently contains:
| Artifact | What it is |
|---|---|
flipdeflock.fap |
Official-firmware Flipper app |
flipdeflock-momentum.fap |
Momentum Flipper app |
flipdeflock-unleashed.fap |
Unleashed Flipper app |
deflock.fap |
RogueMaster Flipper app |
flipdeflock_companion_esp32wroom.bin |
Classic ESP32 companion firmware |
flipdeflock_companion_esp32s2.bin |
ESP32-S2 Wi-Fi-only companion firmware |
flipdeflock_companion_esp32c5_EXPERIMENTAL.bin |
Experimental ESP32-C5 companion firmware |
flipdeflock_asset_pack.zip |
Optional Flipper desktop-animation asset pack |
SHA256SUMS.txt |
Checksums for every release asset |
Anything else distributed under this project's name is not from this project. In
particular, FlipDeFlock ships no Windows .exe, .dll, or .bat, and no executable
archive. The only official ZIP is the named animation asset pack above. A download
link pointing at an archive inside a source directory rather than at a GitHub Release
is a strong sign you are not on the official repository.
If you find a third-party repository distributing something as "FlipDeFlock", please report it to GitHub and let us know. See the name reservation in README.md.