clusterflux-public/SECURITY.md
Clusterflux release 0cf66aaa65 Public release release-e570b80c3a0f
Source commit: e570b80c3a0f4b152a9aa0e7bb8635b3eebcec27

Public tree identity: sha256:cff3388143eb2e9476804cfa1c1246e3a46d485d8aef90f2cdd4df45f2b69abf
2026-07-17 04:58:56 +02:00

839 B

Security reporting

Supported versions

Security fixes are applied to the current main branch and the most recent published Clusterflux release. Older preview releases are not maintained.

Report a vulnerability

Email security@michelpaulissen.com with a concise description, affected version or source revision, reproduction steps, and impact. Do not open a public issue for an unpatched vulnerability or include credentials, session tokens, private keys, provider tokens, customer data, or operator secrets in a public report.

You should receive an acknowledgement within three business days. We will coordinate validation, remediation, release timing, and disclosure with you. Avoid accessing data that is not yours, disrupting the hosted service, or retaining sensitive data beyond what is necessary to demonstrate the issue.