You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: SECURITY.md
+10-8Lines changed: 10 additions & 8 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -3,6 +3,7 @@
3
3
At Flowise, we prioritize security and continuously work to safeguard our systems. However, vulnerabilities can still exist. If you identify a security issue, please report it to us so we can address it promptly. Your cooperation helps us better protect our platform and users.
4
4
5
5
### Scope
6
+
6
7
- Flowise Cloud: cloud.flowiseai.com
7
8
- Public Flowise Repositories
8
9
@@ -31,7 +32,6 @@ At Flowise, we prioritize security and continuously work to safeguard our system
31
32
- Known vulnerabilities in used libraries (unless exploitability can be proven)
32
33
- Static application security testing findings
33
34
34
-
35
35
### Reporting Guidelines
36
36
37
37
- Submit your findings to https://github.com/FlowiseAI/Flowise/security
@@ -46,9 +46,10 @@ At Flowise, we prioritize security and continuously work to safeguard our system
46
46
47
47
### Disclosure Terms
48
48
49
-
The Flowise team believes that transparency is important and public bug bounty reports are a valuable source of knowledge for bug bounty researchers. However, the Flowise team may have legitimate reasons not to disclose vulnerabilities.
49
+
The Flowise team believes that transparency is important and public bug bounty reports are a valuable source of knowledge for bug bounty researchers. However, the Flowise team may have legitimate reasons not to disclose vulnerabilities.
50
50
51
51
Do not discuss or disclose vulnerability information without prior written consent. If you plan on presenting your research, please share a draft with us at least 45 days in advance for review. Avoid including:
52
+
52
53
- Data from any Flowise customer projects
53
54
- Flowise user/customer information
54
55
- Details about Flowise employees, contractors, or partners
@@ -63,7 +64,7 @@ We will validate submissions within the below timelines.
63
64
| Medium | 15 business days |
64
65
| Low | 15 business days |
65
66
66
-
Your report will be kept *confidential*, and your details will not be shared without your consent. The Flowise team will triage and adjust severity or CVSS score if necessary.
67
+
Your report will be kept _confidential_, and your details will not be shared without your consent. The Flowise team will triage and adjust severity or CVSS score if necessary.
67
68
We appreciate your efforts in helping us maintain a secure platform and look forward to working together to resolve any issues responsibly.
68
69
69
70
### Remediation
@@ -72,15 +73,16 @@ Once the report has been verified, the Flowise team will plan the remediation st
72
73
Below is the estimated time to remediate the triaged security reports.
73
74
74
75
| Triaged Severity | Estimated Time to Remediate |
75
-
| ----------------------|---------------- |
76
-
| Critical | 30 business days |
77
-
| High | 60 business days |
78
-
| Medium | 90 business days |
76
+
| ----------------|--------------------------- |
77
+
| Critical | 30 business days|
78
+
| High | 60 business days|
79
+
| Medium | 90 business days|
79
80
80
81
### Public Disclosure Timeline
81
82
82
83
Public Disclosure occurs exactly 30 days after the next official release that includes the security patch. This period gives Flowise users a time to adopt the patched version before technical vulnerability details are made public, mitigating the risk of immediate post-disclosure exploitation.
83
84
84
85
#### Reaching out to the Security team
86
+
85
87
To report a new vulnerability, please submit a Github security Security Advisory report.
86
-
If you have any questions or concerns about the existing Security Advisory, please contact security-team@flowiseai.com.
88
+
If you have any questions or concerns about the existing Security Advisory, please contact security-team@flowiseai.com.
0 commit comments