Skip to content

Security: A-EDev/Flow

Security

SECURITY.md

Security Policy

Supported Versions

The following versions of Flow are currently being supported with security updates.

Version Supported
1.2.x
< 1.2.0

Reporting a Vulnerability

We take the security of Flow seriously. If you believe you have found a security vulnerability, please report it to us privately.

Please do not report security vulnerabilities through public GitHub issues.

Instead, please send an email to flow.aedev@gmail.com.

Please include the following information in your report:

  • Type of issue (e.g., buffer overflow, SQL injection, cross-site scripting, etc.)
  • Full paths of source file(s) related to the manifestation of the issue
  • The location of the affected code (tag/branch/commit or direct URL)
  • Any special configuration required to reproduce the issue
  • Step-by-step instructions to reproduce the issue
  • Proof-of-concept or exploit code (if possible)
  • Impact of the issue, including how an attacker might exploit it

We will acknowledge receipt of your report within 48 hours and provide a timeline for a fix. We ask that you do not disclose the issue publicly until we have had a chance to address it.

There aren’t any published security advisories