Skip to content

Security: FireFightLabs/firefight

Security

SECURITY.md

Security Policy

Reporting a vulnerability

Please report security vulnerabilities privately — do not open a public issue or pull request.

Include what you found, steps to reproduce, and the impact you believe it has. We'll acknowledge your report within 72 hours and keep you informed as we work on a fix.

Scope

Firefight handles incident data, Slack OAuth tokens, and API keys — we treat reports about authentication, authorization, token handling, the public API, and webhook verification with the highest priority.

Supported versions

Security fixes land on the latest release. Self-hosters should track releases (each one documents its upgrade path) — we do not backport fixes to older versions.

There aren't any published security advisories