clusterflux-public/SECURITY.md
Clusterflux release c1769967c1 Public release release-01875e88a3e2
Source commit: 01875e88a3e25379c309489f9f057dd97c0d37de

Public tree identity: sha256:8f37a1aa0cc8f408975daf9cabbe193f8f4c169c6d25e8795e67a3ed5083c76b
2026-07-17 06:09:42 +02:00

18 lines
839 B
Markdown

# Security reporting
## Supported versions
Security fixes are applied to the current main branch and the most recent
published Clusterflux release. Older preview releases are not maintained.
## Report a vulnerability
Email security@michelpaulissen.com with a concise description, affected version
or source revision, reproduction steps, and impact. Do not open a public issue
for an unpatched vulnerability or include credentials, session tokens, private
keys, provider tokens, customer data, or operator secrets in a public report.
You should receive an acknowledgement within three business days. We will
coordinate validation, remediation, release timing, and disclosure with you.
Avoid accessing data that is not yours, disrupting the hosted service, or
retaining sensitive data beyond what is necessary to demonstrate the issue.