Thank you for helping keep Flicker and Emberly secure. This document explains how to report security issues and how we handle reports.
- Preferred: Submit a private security report via GitHub Security Advisories for this repository: https://github.com/EmberlyOSS/Flicker/security/advisories
- Alternatively, you may email [email protected] for confidential reports.
- For non-sensitive discussion or triage, you may also contact us on Discord: https://embrly.ca/discord
- Do NOT post vulnerabilities publicly (issues, PRs, or social media).
When reporting, include:
- A clear description of the issue and impact
- Steps to reproduce (minimal repro if possible)
- Affected versions or commit hashes
- Any PoC code or screenshots
- Your contact email for follow-up (if not using GitHub Advisories)
We will acknowledge reports within 48 hours and provide an estimated timeline for remediation.
This policy covers the uploader (Flicker) desktop application and its associated backend endpoints and APIs managed in this repository.
Please indicate the app version and platform in your report. We prioritize currently supported releases and actively maintained branches.
- We will investigate and, where appropriate, fix confirmed vulnerabilities.
- We will coordinate disclosure with the reporter and, if required, publish a disclosure after a fix is available.
- We will not issue bounties as a rule, but may make exceptions at our discretion.
- Reporter emails
[email protected]with details. - We acknowledge within 48 hours.
- We triage and assign severity and responsible engineers.
- We coordinate a fix and a disclosure timeline with the reporter.
- Once fixed, we publish an advisory (if applicable) and credit the reporter unless they request anonymity.
We ask researchers to follow responsible disclosure: do not exploit or exfiltrate user data while testing. We will not pursue legal action against good-faith security researchers who follow this policy.
If you have questions about this policy, open an issue on the Flicker repo or email [email protected].