Skip to main content

How to report a security vulnerability in Flaggr, what to include, and where official Flaggr software comes from

Last updated October 9, 2026

Security Policy

If you think you've found a security vulnerability in Flaggr, report it privately so it can be fixed before the details are public.

How to report

Email security@flaggr.dev. Flaggr has no public issue tracker, so email is the way to report.

Please don't post the details anywhere public, such as forums, social media, chat channels or issues on any repository, and don't disclose them publicly before a fix is available.

What to include

  • What's affected: the URL or API endpoint, or the npm package and its version
  • Steps to reproduce, or a proof of concept
  • What an attacker could do with it
  • How to reach you with follow-up questions

While you test

  • Use your own accounts, projects and API tokens. Don't access, change or delete data that isn't yours. If you reach someone else's data by accident, stop and say so in your report.
  • Don't degrade the service for other people: no denial-of-service or load testing, and no spam.
  • Don't use social engineering against Flaggr or its users.

Scope

  • The hosted service at flaggr.dev and its subdomains, such as api.flaggr.dev, cdn.flaggr.dev and ingest.flaggr.dev
  • npm packages in the @flaggr scope
  • The SDKs, the CLI and the Terraform provider in the flaggr-dev GitHub organization

Report vulnerabilities in the services Flaggr runs on, such as Vercel, Cloudflare, Firebase or Neon, to those vendors, and issues in third-party dependencies upstream. If one of them affects Flaggr, tell us too.

Official sources

Flaggr software and install instructions come only from:

  • flaggr.dev: the hosted service, these docs and the Claude Code plugin marketplace (https://flaggr.dev/plugins/marketplace.json)
  • cdn.flaggr.dev: the browser scripts
  • npm: packages in the @flaggr scope
  • github.com/flaggr-dev: flaggr-go (the Go SDK, module github.com/flaggr-dev/flaggr-go), flaggr-python (the Python SDK, installed from GitHub: it isn't on PyPI), flaggr-cli (the CLI), terraform-provider-flaggr (the Terraform provider, source flaggr-dev/flaggr) and flaggr-js (a mirror of the source of @flaggr/sdk and @flaggr/evaluator, which are published to npm)

The Flaggr platform's own source code isn't public: it has no public repository, and there's no Flaggr container image (ghcr.io) or plugin marketplace on GitHub. The flaggr account on GitHub belongs to someone else. Only that account can publish to the flaggr namespace on the Terraform Registry, so a provider there isn't Flaggr's either: Flaggr's is flaggr-dev/flaggr, which isn't on the Registry yet (install it from its GitHub release; see Infrastructure as Code). The Flaggr CLI is public at flaggr-dev/flaggr-cli: see CLI for how to install it. If you find code or instructions elsewhere that claim to be Flaggr, report them to security@flaggr.dev.