Skip to content

Security: ph1losof/flashbang

SECURITY.md

Security Policy

Supported versions

Security updates are provided for the latest released version of Flashbang. Users of the hosted service at flashbang.tech receive updates when they are deployed. Self-hosters should update to the latest GitHub release.

Reporting a vulnerability

Please do not report suspected vulnerabilities in a public issue, discussion, or pull request.

Report them privately through GitHub's private vulnerability reporting form. Include as much of the following as possible:

  • A description of the vulnerability and its potential impact
  • The affected version, commit, deployment, or configuration
  • Reproduction steps or a proof of concept
  • Any known mitigations or workarounds

Reports are reviewed on a best-effort basis, and we cannot guarantee a response or resolution timeline. If we investigate the report, we may contact you for more information or to coordinate public disclosure. Please allow a reasonable amount of time for a fix to be developed and released before sharing the vulnerability publicly.

Reports made in good faith to help improve Flashbang's security are welcome.

There aren't any published security advisories