Skip to content

Security: OMT-Global/flow

SECURITY.md

Security Policy

Supported Versions

Unless a repository states otherwise, security fixes target its default branch and latest published release. Experimental, pre-release, and archived repositories may receive fixes only when maintainers can reproduce the issue and a safe repair is practical.

Reporting a Vulnerability

Please do not disclose suspected vulnerabilities in a public issue, discussion, or pull request.

Use GitHub's private vulnerability reporting for the affected repository: open its Security tab, choose Advisories, then select Report a vulnerability. Include:

  • the affected repository, version, commit, or deployment;
  • clear reproduction steps or a proof of concept;
  • the likely impact and required preconditions;
  • any suggested mitigation;
  • whether the report is subject to a disclosure deadline.

If private reporting is not available, open a minimal issue in the affected repository asking a maintainer to establish a private contact channel. Do not include sensitive details in that issue.

We aim to acknowledge complete reports within five business days. Remediation and disclosure timing depend on severity, reproducibility, and maintainer availability. Good-faith research that avoids privacy violations, service disruption, data destruction, and unauthorized access is welcome.

There aren't any published security advisories