We take security vulnerabilities seriously. If you discover a security issue, please report it responsibly.
-
Do NOT open a public issue for security vulnerabilities
-
Email security concerns to:
security@conflow.dev(or create a confidential issue) -
Include as much detail as possible:
-
Description of the vulnerability
-
Steps to reproduce
-
Potential impact
-
Suggested fix (if any)
-
-
Acknowledgment: Within 48 hours of your report
-
Initial Assessment: Within 7 days
-
Resolution Timeline: Depends on severity
-
Critical: 24-48 hours
-
High: 7 days
-
Medium: 30 days
-
Low: 90 days
-
-
All releases are built with
cargo build --release -
Dependencies are audited using
cargo audit -
Binary stripping enabled to reduce attack surface
-
Dependencies are pinned via
Cargo.lock -
Minimal dependency footprint
-
No runtime network access required (offline-first design)
conflow is designed with security-conscious defaults:
-
No automatic code execution without explicit pipeline definition
-
Cache is local-only (no network sync)
-
No telemetry or data collection
-
Sandboxed execution where possible
-
Pipeline definitions can execute arbitrary shell commands via the
shelltool type -
Users should review
.conflow.yamlfiles from untrusted sources before running
-
Primary: security@conflow.dev
-
GitLab Issues: Use confidential issue feature
-
PGP Key: Available upon request