If you discover a security vulnerability, please do not report it through public Issues.
Send vulnerability details to me@simalth.me. We will acknowledge receipt within 48 hours and provide an initial assessment within 7 days.
We ask that you:
- Do not publicly disclose the vulnerability until a fix has been released
- Provide sufficient detail for us to reproduce and verify
- Allow a reasonable timeframe for a fix and release
| Version | Support Status |
|---|---|
| Latest release | Actively supported |
| Pre-release / development | No security updates |
Concord Flash is in early development. Only the latest tagged release receives security fixes.
We will publicly thank reporters after a fix is released (unless you request anonymity).