Skip to content

Security: itzzavdhesh/FlowCraft

Security

SECURITY.md

Security Policy

Supported Versions

The table below details which versions of FlowCraft are currently supported with security updates:

Version Supported
1.x.x
< 1.0.0

Reporting a Vulnerability

The FlowCraft team takes security and user privacy seriously. If you discover a security vulnerability or potential exploit, we appreciate your help in disclosing it to us responsibly.

Responsible Disclosure Guidelines

Please do NOT create a public GitHub issue, pull request, or discussion for security vulnerabilities.

Instead, report vulnerabilities privately through one of the following channels:

  1. GitHub Private Vulnerability Reporting: Use the "Report a vulnerability" button under the Security tab of the repository.
  2. Email Contact: Send a private email to the project maintainers at security@flowcraft.dev.

What to Include in Your Report

To help us evaluate and address the issue quickly, please provide:

  • A clear summary of the vulnerability and its potential impact.
  • Detailed step-by-step instructions, screenshots, or a minimal Proof-of-Concept (PoC) script to reproduce the issue.
  • The browser environment, OS, and version of FlowCraft where the vulnerability was observed.
  • Any proposed remediation or code fix recommendations (if available).

Response Timeline

  • Acknowledgment: We aim to acknowledge receipt of your vulnerability report within 48 hours.
  • Triage & Fix: We will keep you informed as we investigate the vulnerability, work on a patch, and verify the resolution.
  • Public Disclosure: Once a fix is released, we will coordinate public disclosure and credit security researchers who report issues in good faith.

Thank you for contributing to the security and safety of the open-source community!

There aren't any published security advisories