The OwlFlow project team takes the security of our software, connectors, and users seriously.
We actively support the current release version of OwlFlow with security patches:
| Version | Supported |
|---|---|
0.1.x |
✅ |
< 0.1 |
❌ |
If you discover a security vulnerability in OwlFlow, please do not open a public issue. Instead, report it privately:
- Email: Send detailed vulnerability information to
security@divmora.com. - GitHub Security Advisory: Open a private draft security advisory at github.com/divmora/owlflow/security/advisories/new.
Please include:
- A description of the vulnerability and its potential impact.
- Steps to reproduce the issue (proof-of-concept workflow YAML or request payload).
- Any affected components, connectors, or templating logic.
- Any proposed remediation or patch.
- Initial Acknowledgment: Within 48 hours.
- Vulnerability Assessment & Triage: Within 5 business days.
- Remediation & Advisory Release: Coordinated with the reporter before public disclosure.
- Webhook Ingress Security: Always configure and enforce webhook secrets (
secretin workflow trigger definitions) for GitLab tokens or GitHub HMAC SHA-256 signatures. - Credential Management: Do not commit secrets, tokens, or API keys directly in workflow YAML files. Leverage environment variables (
{{ .vars.KEY }}) or IAM roles. - Connector Least Privilege: Scope third-party API tokens (e.g.
GITLAB_TOKEN,JIRA_TOKEN) to the minimum permissions required for automated execution. - Dry-Run & Simulation: Use the OwlFlow Studio simulator to validate conditions and template transformations prior to deploying workflows to live production environments.