Skip to content

Security: fixture-dev/lash

Security

SECURITY.md

Security Policy

Fixture takes the security of its products and services seriously. We appreciate responsible disclosure of vulnerabilities.

Reporting a vulnerability

Please do not report security vulnerabilities in public GitHub issues.

Instead, report them privately through our contact form. Include the word "Security" in the subject so we can prioritize it, along with:

  • A description of the vulnerability and its potential impact
  • Steps to reproduce (proof-of-concept code or commands are welcome)
  • The product and version affected (e.g. Flawd CLI version, or fixture.dev itself)

We will acknowledge your report within 3 business days and keep you informed as we investigate and remediate.

Scope

This policy covers:

  • Flawd — the CLI and its evaluation/licensing flow
  • fixture.dev — the website, its APIs, and the customer portal
  • Any repository published under the fixture-dev organization

Our commitment

  • We will not pursue legal action against good-faith security research that respects user privacy and avoids service disruption.
  • We will credit reporters who wish to be credited once a fix is released.

There aren't any published security advisories