Skip to content

Security Policy

Reporting a vulnerability

Do not publish exploitable vulnerability details, credentials, tokens, private keys, or sensitive provider information in a public issue.

Use GitHub private security reporting when available. Until that channel is enabled, contact the repository owner through a private Fuzzy Technologies channel.

Scope

Security reports should describe vulnerabilities in F-Layer itself: its code, generated artifacts, provider integration boundaries, lifecycle behavior, configuration/state handling, or release artifacts.

Misconfiguration or compromise of infrastructure independently managed by a user is not automatically an F-Layer vulnerability, although reproducible unsafe defaults or defects in generated configuration should be reported.

Development boundary

Tests must not mutate or probe real third-party infrastructure without explicit authorization. Use repository-defined synthetic fixtures, mocks, and isolated test resources by default.

Repository source