Skip to content

Security: takasoft/floe

Security

SECURITY.md

Security Policy

Supported versions

Floe is pre-1.0 and under active development. Security fixes are applied to the latest released minor version on the main branch. Older versions are not maintained.

Version Supported
0.1.x
< 0.1

Reporting a vulnerability

Please do not report security vulnerabilities through public GitHub issues, discussions, or pull requests.

Instead, report them privately through GitHub's built-in private vulnerability reporting:

  1. Go to the Security tab of the repository.
  2. Click Report a vulnerability to open a private advisory.

Please include as much of the following as you can:

  • A description of the vulnerability and its impact.
  • Steps to reproduce, or a proof-of-concept.
  • The affected version(s) and environment details.
  • Any suggested remediation, if you have one.

You can expect an initial acknowledgement within a few days. We will keep you informed as we investigate and work on a fix, and we will credit you in the release notes unless you ask us not to.

Thank you for helping keep Floe and its users safe.

There aren't any published security advisories