Flower is pre-1.0 software. Security fixes are handled on the active main
branch and on any release line explicitly marked as supported.
Please do not report suspected vulnerabilities in a public issue.
Use GitHub's private vulnerability reporting for this repository if it is
available. If that is not available, email the maintainer listed in pom.xml.
Include:
- Affected module and version or commit.
- A short description of the risk.
- Reproduction steps or a minimal proof of concept.
- Any known workaround.
Reports are handled on a best-effort basis. Public disclosure should wait until a fix or mitigation is available.