Skip to content

Security: Ghost-Frame/FrameShift

SECURITY.md

Security Policy

FrameShift is currently prerelease software. Security fixes are made against the current code and latest prerelease; older prereleases do not receive a separate support guarantee.

Report a vulnerability

Use GitHub's private vulnerability reporting form:

https://github.com/Ghost-Frame/FrameShift/security/advisories/new

Do not open a public issue for a suspected vulnerability. Include the affected component and version, impact, reproduction steps, relevant environment details, and any suggested remediation. Avoid including live credentials, private keys, tokens, or other secrets.

The maintainers will coordinate through the private advisory. FrameShift does not promise a fixed response or disclosure timeline.

This channel covers the core Ghost-Frame/FrameShift repository. For a vulnerability in a separately maintained website, desktop application, or other repository, use that repository's reporting channel.

There aren't any published security advisories