Source commit: 69fccd306838141ba9b1730f4ac4afb1a617bb4e Public tree identity: sha256:8c03637496d3f7ee1b625aa1c823cd69bfcf0247a061d8cb571e05d537329691
844 B
Security reporting
Supported versions
Security fixes are applied to the current main branch and the most recent published Clusterflux release. Older preview releases are not maintained.
Report a vulnerability
Email security@clusterflux.lesstuff.com with a concise description, affected version or source revision, reproduction steps, and impact. Do not open a public issue for an unpatched vulnerability or include credentials, session tokens, private keys, provider tokens, customer data, or operator secrets in a public report.
You should receive an acknowledgement within three business days. We will coordinate validation, remediation, release timing, and disclosure with you. Avoid accessing data that is not yours, disrupting the hosted service, or retaining sensitive data beyond what is necessary to demonstrate the issue.