| Version | Supported |
|---|---|
| 0.0.x | ✅ |
Femto is a local terminal application, so the attack surface is relatively small. However, if you discover a security vulnerability (e.g., arbitrary code execution via a malicious file payload, path traversal on save), please do the following:
- DO NOT open a public GitHub Issue.
- Email the maintainer directly at [[email protected]] with the subject "Femto Security".
- Include a detailed description of the vulnerability and steps to reproduce it.
You will receive an acknowledgment within 48 hours. We will work with you to understand the scope and release a patch as quickly as possible.