Skip to content

Security: codewithzaqar/femto

Security

.github/SECURITY.md

Security Policy

Supported Versions

Version Supported
0.0.x ✅

Reporting a Vulnerability

Femto is a local terminal application, so the attack surface is relatively small. However, if you discover a security vulnerability (e.g., arbitrary code execution via a malicious file payload, path traversal on save), please do the following:

  1. DO NOT open a public GitHub Issue.
  2. Email the maintainer directly at [[email protected]] with the subject "Femto Security".
  3. Include a detailed description of the vulnerability and steps to reproduce it.

You will receive an acknowledgment within 48 hours. We will work with you to understand the scope and release a patch as quickly as possible.

There aren't any published security advisories