Skip to content

Security: hang-in/tunaFlow

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

Please report vulnerabilities privately to: d9ng@outlook.com

Do not open a public GitHub issue for security reports.

What to include

  • Affected version / commit SHA
  • Reproduction steps
  • Impact assessment (data exposure, RCE, privilege escalation, etc.)
  • Suggested fix (optional)

Response timeline

Stage Target
Initial acknowledgement within 3 days
Severity triage within 7 days
Fix or mitigation plan within 30 days for high/critical

Supported versions

tunaFlow is in beta. Only the latest release receives security fixes.

Out of scope

  • Issues in upstream dependencies (report to the respective projects)
  • Attacks requiring physical access to the user's machine
  • Social engineering of project maintainers

Disclosure

Coordinated disclosure is preferred. We will credit reporters in the release notes unless anonymity is requested.

There aren't any published security advisories