Skip to content

Security: riffcc/dragonfly

SECURITY.md

Security Policy

Supported Versions

We are currently supporting the following versions:

Version Supported
v0.1.x

Note, at this early stage of development, we may not backport patches to old minor versions.

In this case, to remain secure you will need to update to the latest version of Dragonfly.

Reporting a Vulnerability

Please email security@dragonfly.computer with the details of the security issue or vulnerability.

We'll review it, tell you if our findings match yours, and issue a patch or documentation to correct the issue.

Responsible Disclosure

For critical issues, please avoid opening public issues or posts that might risk exposing the security vulnerability prior to a patch being released.

Standard responsible disclosure rules apply.

For minor issues or concerns that you believe have small or no impact, you may post them as issues in the Dragonfly issue tracker on GitHub.

We are committed to transparency - any issues disclosed will be publicly fixed or acknowledged once safe.

Incident response

In the event of a major bug being reported and confirmed, we will issue a notice to Dragonfly users and customers informing them that a new version will be released at YYYY-MM-DD at time X (timezone GMT+ZZ) and that it will contain critical security updates, advising all users to upgrade immediately.

There aren’t any published security advisories