The table below details which versions of FlowCraft are currently supported with security updates:
| Version | Supported |
|---|---|
| 1.x.x | ✅ |
| < 1.0.0 | ❌ |
The FlowCraft team takes security and user privacy seriously. If you discover a security vulnerability or potential exploit, we appreciate your help in disclosing it to us responsibly.
Please do NOT create a public GitHub issue, pull request, or discussion for security vulnerabilities.
Instead, report vulnerabilities privately through one of the following channels:
- GitHub Private Vulnerability Reporting: Use the "Report a vulnerability" button under the Security tab of the repository.
- Email Contact: Send a private email to the project maintainers at
security@flowcraft.dev.
To help us evaluate and address the issue quickly, please provide:
- A clear summary of the vulnerability and its potential impact.
- Detailed step-by-step instructions, screenshots, or a minimal Proof-of-Concept (PoC) script to reproduce the issue.
- The browser environment, OS, and version of FlowCraft where the vulnerability was observed.
- Any proposed remediation or code fix recommendations (if available).
- Acknowledgment: We aim to acknowledge receipt of your vulnerability report within 48 hours.
- Triage & Fix: We will keep you informed as we investigate the vulnerability, work on a patch, and verify the resolution.
- Public Disclosure: Once a fix is released, we will coordinate public disclosure and credit security researchers who report issues in good faith.
Thank you for contributing to the security and safety of the open-source community!