Source commit: b215a8f6e506fafa38755d1c14e89e5a52c82f9f Public tree identity: sha256:23ba19e9f6e902cbfb4ed34cd7f9e1aaa39945e9b61946b879d7254b3f033502
18 lines
839 B
Markdown
18 lines
839 B
Markdown
# Security reporting
|
|
|
|
## Supported versions
|
|
|
|
Security fixes are applied to the current main branch and the most recent
|
|
published Clusterflux release. Older preview releases are not maintained.
|
|
|
|
## Report a vulnerability
|
|
|
|
Email security@michelpaulissen.com with a concise description, affected version
|
|
or source revision, reproduction steps, and impact. Do not open a public issue
|
|
for an unpatched vulnerability or include credentials, session tokens, private
|
|
keys, provider tokens, customer data, or operator secrets in a public report.
|
|
|
|
You should receive an acknowledgement within three business days. We will
|
|
coordinate validation, remediation, release timing, and disclosure with you.
|
|
Avoid accessing data that is not yours, disrupting the hosted service, or
|
|
retaining sensitive data beyond what is necessary to demonstrate the issue.
|