clusterflux-public/SECURITY.md
Clusterflux release e695caf17b Public release release-a687c9883a0f
Source commit: a687c9883a0f7bafcbd43836bc484a1920a05029

Public tree identity: sha256:763e679bed9bbb2b69561e13bec82913af2a523960b32194fa13373e10d5a297
2026-07-19 11:41:19 +02:00

839 B

Security reporting

Supported versions

Security fixes are applied to the current main branch and the most recent published Clusterflux release. Older preview releases are not maintained.

Report a vulnerability

Email security@michelpaulissen.com with a concise description, affected version or source revision, reproduction steps, and impact. Do not open a public issue for an unpatched vulnerability or include credentials, session tokens, private keys, provider tokens, customer data, or operator secrets in a public report.

You should receive an acknowledgement within three business days. We will coordinate validation, remediation, release timing, and disclosure with you. Avoid accessing data that is not yours, disrupting the hosted service, or retaining sensitive data beyond what is necessary to demonstrate the issue.