Public release release-ce2d9c9dc397

Source commit: ce2d9c9dc3979543dd4e40b29e7fba2d55cc8633

Public tree identity: sha256:168e259dfbcbf75b34d46c1c641fd448e474550988c1d2eda802826bf103c0bc
This commit is contained in:
Clusterflux release 2026-07-19 13:31:53 +02:00
commit 2927ca6912
221 changed files with 81097 additions and 0 deletions

18
SECURITY.md Normal file
View file

@ -0,0 +1,18 @@
# Security reporting
## Supported versions
Security fixes are applied to the current main branch and the most recent
published Clusterflux release. Older preview releases are not maintained.
## Report a vulnerability
Email security@michelpaulissen.com with a concise description, affected version
or source revision, reproduction steps, and impact. Do not open a public issue
for an unpatched vulnerability or include credentials, session tokens, private
keys, provider tokens, customer data, or operator secrets in a public report.
You should receive an acknowledgement within three business days. We will
coordinate validation, remediation, release timing, and disclosure with you.
Avoid accessing data that is not yours, disrupting the hosted service, or
retaining sensitive data beyond what is necessary to demonstrate the issue.