Skip to content

Security: Flowfin/core

Security

SECURITY.md

Reporting a security problem

Use the private reporting form under Security on the repository the problem is in. It is enabled on every repository in this organisation. The report stays between you and the maintainer until there is a fix, and GitHub notifies you when something changes.

Please do not open a public issue for a security problem, and please do not post a working exploit anywhere public before a fix exists.

What helps

The version you ran, the server line, and what an attacker would gain. A rough description of the path is more useful than a polished writeup that arrives a week later.

What to expect

A first answer within a few days. If a report turns out to be a real problem, the fix and the advisory are published together, and the report gets credit unless you ask otherwise.

Scope

Everything in this organisation. A problem in Jellyfin itself belongs to the Jellyfin project, not here, though a report that lands in the wrong place will be pointed the right way rather than closed.

There aren't any published security advisories