Skip to content

Security: floci-io/.github

Security

SECURITY.md

Security Policy

We take the security of Floci and its users seriously. Thank you for helping keep the project and its community safe.

Reporting a vulnerability

Please do not report security vulnerabilities through public GitHub issues, discussions, or pull requests.

Instead, report them privately by email to security@floci.io. Where possible, include:

  • The affected component (which emulator/repo and version, or image tag).
  • A description of the vulnerability and its impact.
  • Steps to reproduce, a proof of concept, or affected source paths.
  • Any suggested remediation, if you have one.

If you prefer, you may also use GitHub's private vulnerability reporting on the relevant repository.

Coordinated disclosure

We follow a 90-day coordinated disclosure model:

  • We aim to acknowledge your report promptly and keep you updated as we investigate.
  • We will work with you on a fix and a disclosure timeline, targeting a public advisory within 90 days of the initial report.
  • We ask that you give us a reasonable opportunity to remediate before any public disclosure, and we are happy to credit you in the advisory unless you'd prefer to remain anonymous.

Scope

This policy applies to the Floci emulators (AWS, Azure, GCP, OCI), client libraries, and supporting tooling published under the floci-io organization.

There aren't any published security advisories