Skip to content

Security: venaissance/tiny-flow

Security

SECURITY.md

Security Policy

Supported Versions

Version Supported
0.1.x ✅

Reporting a Vulnerability

We take security seriously. If you discover a vulnerability, please report it responsibly.

Do NOT open a public GitHub issue for security vulnerabilities.

How to Report

  1. GitHub Security Advisories (preferred): Go to Security Advisories and click "Report a vulnerability".
  2. Email: Send details to security@venaissance.dev.

What to Include

  • Description of the vulnerability
  • Steps to reproduce
  • Potential impact
  • Suggested fix (if any)

Response Timeline

Action Timeline
Acknowledgment 48 hours
Initial assessment 3 days
Fix plan communicated 7 days
Patch released 30 days

Disclosure Policy

  • We follow coordinated disclosure. Please allow us reasonable time to address the issue before public disclosure.
  • Credit will be given to reporters unless anonymity is requested.

Thank you for helping keep TinyFlow and its users safe.

There aren't any published security advisories