Skip to content

Security: zagaaam-ops/FlowFiles

Security

SECURITY.md

Security Policy

Supported Versions

At this stage, FlowFiles is under active development.

Security updates will be provided for the latest development version until the first stable release (v1.0).

Version Supported
v1.x ✅ Yes
v0.x 🚧 Development
Older Versions ❌ No

Reporting a Security Vulnerability

If you discover a security issue, please do not create a public GitHub issue.

Instead:

  1. Contact the project maintainer privately.
  2. Include a detailed description of the vulnerability.
  3. Provide reproduction steps if possible.
  4. Include screenshots or logs when appropriate.

The report should include:

  • Platform (Windows, Linux, macOS, Android, iOS)
  • Application version
  • Steps to reproduce
  • Expected behavior
  • Actual behavior
  • Potential impact

Security Principles

FlowFiles is designed with the following principles:

  • Privacy first
  • Offline first
  • No unnecessary data collection
  • Least privilege
  • Secure file operations
  • Transparent open-source development

Future Security Goals

The project aims to implement:

  • Secure file permissions
  • Safe drag-and-drop operations
  • Secure temporary file handling
  • Dependency vulnerability scanning
  • Automated security analysis
  • Code signing for releases

Responsible Disclosure

Please allow reasonable time for security issues to be investigated and resolved before public disclosure.

We appreciate responsible reporting and will acknowledge contributors who help improve the project's security.

There aren't any published security advisories