We take the security of Floci and its users seriously. Thank you for helping keep the project and its community safe.
Please do not report security vulnerabilities through public GitHub issues, discussions, or pull requests.
Instead, report them privately by email to security@floci.io. Where possible, include:
- The affected component (which emulator/repo and version, or image tag).
- A description of the vulnerability and its impact.
- Steps to reproduce, a proof of concept, or affected source paths.
- Any suggested remediation, if you have one.
If you prefer, you may also use GitHub's private vulnerability reporting on the relevant repository.
We follow a 90-day coordinated disclosure model:
- We aim to acknowledge your report promptly and keep you updated as we investigate.
- We will work with you on a fix and a disclosure timeline, targeting a public advisory within 90 days of the initial report.
- We ask that you give us a reasonable opportunity to remediate before any public disclosure, and we are happy to credit you in the advisory unless you'd prefer to remain anonymous.
This policy applies to the Floci emulators (AWS, Azure, GCP, OCI), client libraries, and supporting tooling published under the floci-io organization.