Skip to content

Security: exterminatorrat/Fleck

SECURITY.md

Security policy

Supported versions

Fleck has not published a supported release. Source snapshots and local Developer Preview builds receive no guaranteed security updates. The project does not promise a response, remediation, disclosure, or update timeline.

Reporting a vulnerability

Report a security vulnerability through GitHub private vulnerability reporting. GitHub requires the reporter to sign in, so an unauthenticated visit redirects to GitHub's login page. Do not include vulnerability details, private data, credentials, or an exploit in a public issue, pull request, discussion, or other public channel.

GitHub private vulnerability reporting is enabled. The owner confirmed that an outside test report was submitted privately and that its maintainer notification was visible. This verifies that the private route delivered that test; it does not promise a response, remediation, disclosure, or update timeline.

Public issues and pull requests are open for ordinary bugs and contributions, not vulnerabilities. If the private reporting form is unavailable, keep sensitive details private rather than disclosing them through a public channel.

This vulnerability-reporting route is for security reports, not conduct reports. Send private conduct reports to Harry, as described in the Code of Conduct, rather than through GitHub private vulnerability reporting. The owner approved that address and confirmed that a conduct test email was visible in the receiving inbox. No response or resolution timeline is promised.

There aren't any published security advisories