OttoFlow follows semantic versioning. Security fixes are backported to the latest minor release; older releases are not supported.
Please do not report security vulnerabilities through public GitHub issues.
Instead, report it privately via GitHub Security Advisories.
Include, if possible:
- A description of the vulnerability and its potential impact
- Steps to reproduce
- Affected version(s)
We aim to acknowledge new reports within 5 business days and to keep you informed as we investigate and prepare a fix. Once a fix is available, we'll coordinate disclosure timing with you and credit reporters (unless anonymity is requested) in the release notes and/or a GitHub Security Advisory.
Release archives publish a checksums.txt; verify a download before running it:
sha256sum --ignore-missing -c checksums.txtEvery change is scanned by CodeQL and kept current by Dependabot.