Please do not open a public issue for a suspected vulnerability.
Use GitHub's private vulnerability reporting form. If that form is unavailable, email support@flarmio.com with:
- A concise description and likely impact
- Reproduction steps or a proof of concept
- Affected commit, version, platform, and device where known
- Any suggested mitigation
- How you would like to be credited
We aim to acknowledge reports within five business days. We will investigate, coordinate a fix and disclosure timeline, and keep you updated when there is material progress. Timelines may vary because StoneSiege is currently a small alpha project.
Security fixes target the latest source on main and the latest official internal-testing build. Old commits, unofficial forks, modified builds, and third-party services are outside the project's support scope.
Act in good faith. Do not access, retain, or publish another person's data; disrupt services; use social engineering; or test systems you do not own without permission. Stop once you have enough evidence to report the issue. We will not pursue action against good-faith research that follows this policy.
Signing keys, store credentials, access tokens, personal information, and accidentally committed secrets should always be reported privately and immediately.