Please report security vulnerabilities privately — do not open a public issue or pull request.
- Email: security@firefight.app
- Or use GitHub's private vulnerability reporting on this repository.
Include what you found, steps to reproduce, and the impact you believe it has. We'll acknowledge your report within 72 hours and keep you informed as we work on a fix.
Firefight handles incident data, Slack OAuth tokens, and API keys — we treat reports about authentication, authorization, token handling, the public API, and webhook verification with the highest priority.
Security fixes land on the latest release. Self-hosters should track releases (each one documents its upgrade path) — we do not backport fixes to older versions.