Security: flooooooooooow/flow

Security

SECURITY.md

Security Policy

Supported Versions

Flow is still on the pre-1.0 development line. Until 1.0.0 ships, only the latest 0.x release line receives fixes.

VersionSupported
0.12.x✅ current pre-1.0 line
< 0.12

When Flow 1.0 ships, the support policy becomes:

VersionSupport
latest 1.x minor✅ bug and security fixes
previous 1.x minor✅ security fixes for 90 days after the next minor release
older 1.x minors
0.x✅ security fixes for 90 days after 1.0.0, then ❌

A security or correctness issue may require an otherwise incompatible change in a supported release when preserving the old behaviour would leave users exposed to a material vulnerability, memory-safety defect, miscompilation, or similarly serious failure. Such changes must be called out prominently in release notes.

Reporting a Vulnerability

Do not open a public GitHub issue for security vulnerabilities.

Please report via one of:

  1. GitHub Security AdvisoriesReport a vulnerability on this repository
  2. Email the maintainer listed on the GitHub org / profile if advisories are unavailable

Include:

  • Affected version / commit
  • Reproduction steps or PoC (as minimal as practical)
  • Impact assessment (RCE, path traversal, sandbox escape, denial of service, etc.)

Response

We aim to acknowledge reports within 7 days and to ship a fix or mitigation for confirmed high-severity issues as soon as practical. Coordinated disclosure is preferred; please give us a reasonable window before public write-ups.

Scope

In scope: the flow CLI, compiler (src/flow/, compiler/), runtime, stdlib, release/build tooling, and official packages as shipped from this repository.

Security-sensitive compiler/tooling areas include subprocess construction, temporary/build paths, symlink and path traversal handling, imports/includes, archive extraction, package/dependency downloads, plugin loading, hostile-source resource exhaustion, and unsafe FFI boundaries.

Out of scope: third-party packages under registry/ that are not part of a release artifact, and VPS / personal site infrastructure.

Flow 1.0 threat model

The Stable Flow 1.0 compiler must be able to parse, resolve, type-check and lower hostile source without command injection, filesystem traversal or unintended host code execution. Resource-exhaustion and semantic-divergence resistance are qualified separately by the release fuzz programme.

Compiling source and executing source are different trust decisions. flow run deliberately compiles and executes the supplied program with the invoking user's privileges; it is not a sandbox. Likewise, extern, raw pointers and other native FFI facilities are trusted-code boundaries and can perform arbitrary process-visible actions. The local playground/native compile server is development tooling, not a remote multi-tenant execution sandbox.

Surface1.0 security position
Stable compiler pipelineHostile source must not become a shell command, escape permitted import roots, or execute host code merely by being compiled.
Stable subprocessesCompiler/tool invocations use argument vectors rather than shell interpolation. Repository tests reject shell=True, os.system and os.popen under src/flow.
Temporary build stateStable Python tooling uses race-resistant temporary APIs. tempfile.mktemp is forbidden under src/flow.
Module importsStable local resolution stays inside the selected project, stdlib and package roots. Legacy string imports reject absolute, home-relative and parent-traversing paths.
flow runNative execution boundary, not sandboxed. Program exit status is propagated once execution begins.
FFI / externTrusted native boundary, outside safe-source containment guarantees.
Package/dependency acquisitionDependency source and extraction semantics remain Experimental until integrity, symlink and root-containment rules are qualified.
Release artifactsBuilt from a clean checkout, freshness-checked, checksummed, unpacked and exercised before publication. Provenance/signing work is tracked by #652.
Experimental JIT/GPU/hardware pathsDo not inherit the Stable 1.0 security guarantee unless separately promoted.

Release threat review

The release review explicitly covers shell/process injection, import and archive path traversal, temporary-file races, hostile-source crashes or hangs, stale or substituted release artifacts, unsafe native boundaries, and package extraction escapes. New package extraction code promoted to Stable must reject absolute archive members, .. traversal, and symlink-mediated writes outside the package root with regression coverage.

User-supplied compiler/linker flags are an explicit advanced trust boundary: they may intentionally alter compilation, but source text, module names and package metadata must never be implicitly interpolated into shell command strings.

For each release candidate, dependency/static security scans, Stable security invariant tests, self-host qualification and long-fuzz results are reviewed together. A finding is release-severity when it permits unintended host command execution, filesystem escape, artifact substitution, credential disclosure, reliable memory corruption in a Stable compiler/runtime component, or a comparably serious violation of this documented boundary.

Release security gate

Flow 1.0.0 must not ship with a known unresolved critical or high-severity vulnerability in a Stable component. Release qualification also requires the dependency audit and security scans defined in CI, plus disposition of relevant findings from release fuzzing.

Tracking: #650 and the Flow 1.0 stabilisation programme #653.

There aren't any published security advisories

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Security: flooooooooooow/flow

Security

SECURITY.md

Security Policy

Supported Versions

Flow is still on the pre-1.0 development line. Until 1.0.0 ships, only the latest 0.x release line receives fixes.

VersionSupported
0.12.x✅ current pre-1.0 line
< 0.12

When Flow 1.0 ships, the support policy becomes:

VersionSupport
latest 1.x minor✅ bug and security fixes
previous 1.x minor✅ security fixes for 90 days after the next minor release
older 1.x minors
0.x✅ security fixes for 90 days after 1.0.0, then ❌

A security or correctness issue may require an otherwise incompatible change in a supported release when preserving the old behaviour would leave users exposed to a material vulnerability, memory-safety defect, miscompilation, or similarly serious failure. Such changes must be called out prominently in release notes.

Reporting a Vulnerability

Do not open a public GitHub issue for security vulnerabilities.

Please report via one of:

  1. GitHub Security AdvisoriesReport a vulnerability on this repository
  2. Email the maintainer listed on the GitHub org / profile if advisories are unavailable

Include:

  • Affected version / commit
  • Reproduction steps or PoC (as minimal as practical)
  • Impact assessment (RCE, path traversal, sandbox escape, denial of service, etc.)

Response

We aim to acknowledge reports within 7 days and to ship a fix or mitigation for confirmed high-severity issues as soon as practical. Coordinated disclosure is preferred; please give us a reasonable window before public write-ups.

Scope

In scope: the flow CLI, compiler (src/flow/, compiler/), runtime, stdlib, release/build tooling, and official packages as shipped from this repository.

Security-sensitive compiler/tooling areas include subprocess construction, temporary/build paths, symlink and path traversal handling, imports/includes, archive extraction, package/dependency downloads, plugin loading, hostile-source resource exhaustion, and unsafe FFI boundaries.

Out of scope: third-party packages under registry/ that are not part of a release artifact, and VPS / personal site infrastructure.

Flow 1.0 threat model

The Stable Flow 1.0 compiler must be able to parse, resolve, type-check and lower hostile source without command injection, filesystem traversal or unintended host code execution. Resource-exhaustion and semantic-divergence resistance are qualified separately by the release fuzz programme.

Compiling source and executing source are different trust decisions. flow run deliberately compiles and executes the supplied program with the invoking user's privileges; it is not a sandbox. Likewise, extern, raw pointers and other native FFI facilities are trusted-code boundaries and can perform arbitrary process-visible actions. The local playground/native compile server is development tooling, not a remote multi-tenant execution sandbox.

Surface1.0 security position
Stable compiler pipelineHostile source must not become a shell command, escape permitted import roots, or execute host code merely by being compiled.
Stable subprocessesCompiler/tool invocations use argument vectors rather than shell interpolation. Repository tests reject shell=True, os.system and os.popen under src/flow.
Temporary build stateStable Python tooling uses race-resistant temporary APIs. tempfile.mktemp is forbidden under src/flow.
Module importsStable local resolution stays inside the selected project, stdlib and package roots. Legacy string imports reject absolute, home-relative and parent-traversing paths.
flow runNative execution boundary, not sandboxed. Program exit status is propagated once execution begins.
FFI / externTrusted native boundary, outside safe-source containment guarantees.
Package/dependency acquisitionDependency source and extraction semantics remain Experimental until integrity, symlink and root-containment rules are qualified.
Release artifactsBuilt from a clean checkout, freshness-checked, checksummed, unpacked and exercised before publication. Provenance/signing work is tracked by #652.
Experimental JIT/GPU/hardware pathsDo not inherit the Stable 1.0 security guarantee unless separately promoted.

Release threat review

The release review explicitly covers shell/process injection, import and archive path traversal, temporary-file races, hostile-source crashes or hangs, stale or substituted release artifacts, unsafe native boundaries, and package extraction escapes. New package extraction code promoted to Stable must reject absolute archive members, .. traversal, and symlink-mediated writes outside the package root with regression coverage.

User-supplied compiler/linker flags are an explicit advanced trust boundary: they may intentionally alter compilation, but source text, module names and package metadata must never be implicitly interpolated into shell command strings.

For each release candidate, dependency/static security scans, Stable security invariant tests, self-host qualification and long-fuzz results are reviewed together. A finding is release-severity when it permits unintended host command execution, filesystem escape, artifact substitution, credential disclosure, reliable memory corruption in a Stable compiler/runtime component, or a comparably serious violation of this documented boundary.

Release security gate

Flow 1.0.0 must not ship with a known unresolved critical or high-severity vulnerability in a Stable component. Release qualification also requires the dependency audit and security scans defined in CI, plus disposition of relevant findings from release fuzzing.

Tracking: #650 and the Flow 1.0 stabilisation programme #653.

There aren't any published security advisories

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Security: flooooooooooow/flow

Security

SECURITY.md

Security Policy

Supported Versions

Flow is still on the pre-1.0 development line. Until 1.0.0 ships, only the latest 0.x release line receives fixes.

VersionSupported
0.12.x✅ current pre-1.0 line
< 0.12

When Flow 1.0 ships, the support policy becomes:

VersionSupport
latest 1.x minor✅ bug and security fixes
previous 1.x minor✅ security fixes for 90 days after the next minor release
older 1.x minors
0.x✅ security fixes for 90 days after 1.0.0, then ❌

A security or correctness issue may require an otherwise incompatible change in a supported release when preserving the old behaviour would leave users exposed to a material vulnerability, memory-safety defect, miscompilation, or similarly serious failure. Such changes must be called out prominently in release notes.

Reporting a Vulnerability

Do not open a public GitHub issue for security vulnerabilities.

Please report via one of:

  1. GitHub Security AdvisoriesReport a vulnerability on this repository
  2. Email the maintainer listed on the GitHub org / profile if advisories are unavailable

Include:

  • Affected version / commit
  • Reproduction steps or PoC (as minimal as practical)
  • Impact assessment (RCE, path traversal, sandbox escape, denial of service, etc.)

Response

We aim to acknowledge reports within 7 days and to ship a fix or mitigation for confirmed high-severity issues as soon as practical. Coordinated disclosure is preferred; please give us a reasonable window before public write-ups.

Scope

In scope: the flow CLI, compiler (src/flow/, compiler/), runtime, stdlib, release/build tooling, and official packages as shipped from this repository.

Security-sensitive compiler/tooling areas include subprocess construction, temporary/build paths, symlink and path traversal handling, imports/includes, archive extraction, package/dependency downloads, plugin loading, hostile-source resource exhaustion, and unsafe FFI boundaries.

Out of scope: third-party packages under registry/ that are not part of a release artifact, and VPS / personal site infrastructure.

Flow 1.0 threat model

The Stable Flow 1.0 compiler must be able to parse, resolve, type-check and lower hostile source without command injection, filesystem traversal or unintended host code execution. Resource-exhaustion and semantic-divergence resistance are qualified separately by the release fuzz programme.

Compiling source and executing source are different trust decisions. flow run deliberately compiles and executes the supplied program with the invoking user's privileges; it is not a sandbox. Likewise, extern, raw pointers and other native FFI facilities are trusted-code boundaries and can perform arbitrary process-visible actions. The local playground/native compile server is development tooling, not a remote multi-tenant execution sandbox.

Surface1.0 security position
Stable compiler pipelineHostile source must not become a shell command, escape permitted import roots, or execute host code merely by being compiled.
Stable subprocessesCompiler/tool invocations use argument vectors rather than shell interpolation. Repository tests reject shell=True, os.system and os.popen under src/flow.
Temporary build stateStable Python tooling uses race-resistant temporary APIs. tempfile.mktemp is forbidden under src/flow.
Module importsStable local resolution stays inside the selected project, stdlib and package roots. Legacy string imports reject absolute, home-relative and parent-traversing paths.
flow runNative execution boundary, not sandboxed. Program exit status is propagated once execution begins.
FFI / externTrusted native boundary, outside safe-source containment guarantees.
Package/dependency acquisitionDependency source and extraction semantics remain Experimental until integrity, symlink and root-containment rules are qualified.
Release artifactsBuilt from a clean checkout, freshness-checked, checksummed, unpacked and exercised before publication. Provenance/signing work is tracked by #652.
Experimental JIT/GPU/hardware pathsDo not inherit the Stable 1.0 security guarantee unless separately promoted.

Release threat review

The release review explicitly covers shell/process injection, import and archive path traversal, temporary-file races, hostile-source crashes or hangs, stale or substituted release artifacts, unsafe native boundaries, and package extraction escapes. New package extraction code promoted to Stable must reject absolute archive members, .. traversal, and symlink-mediated writes outside the package root with regression coverage.

User-supplied compiler/linker flags are an explicit advanced trust boundary: they may intentionally alter compilation, but source text, module names and package metadata must never be implicitly interpolated into shell command strings.

For each release candidate, dependency/static security scans, Stable security invariant tests, self-host qualification and long-fuzz results are reviewed together. A finding is release-severity when it permits unintended host command execution, filesystem escape, artifact substitution, credential disclosure, reliable memory corruption in a Stable compiler/runtime component, or a comparably serious violation of this documented boundary.

Release security gate

Flow 1.0.0 must not ship with a known unresolved critical or high-severity vulnerability in a Stable component. Release qualification also requires the dependency audit and security scans defined in CI, plus disposition of relevant findings from release fuzzing.

Tracking: #650 and the Flow 1.0 stabilisation programme #653.

There aren't any published security advisories

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Security: flooooooooooow/flow

Security

SECURITY.md

Security Policy

Supported Versions

Flow is still on the pre-1.0 development line. Until 1.0.0 ships, only the latest 0.x release line receives fixes.

VersionSupported
0.12.x✅ current pre-1.0 line
< 0.12

When Flow 1.0 ships, the support policy becomes:

VersionSupport
latest 1.x minor✅ bug and security fixes
previous 1.x minor✅ security fixes for 90 days after the next minor release
older 1.x minors
0.x✅ security fixes for 90 days after 1.0.0, then ❌

A security or correctness issue may require an otherwise incompatible change in a supported release when preserving the old behaviour would leave users exposed to a material vulnerability, memory-safety defect, miscompilation, or similarly serious failure. Such changes must be called out prominently in release notes.

Reporting a Vulnerability

Do not open a public GitHub issue for security vulnerabilities.

Please report via one of:

  1. GitHub Security AdvisoriesReport a vulnerability on this repository
  2. Email the maintainer listed on the GitHub org / profile if advisories are unavailable

Include:

  • Affected version / commit
  • Reproduction steps or PoC (as minimal as practical)
  • Impact assessment (RCE, path traversal, sandbox escape, denial of service, etc.)

Response

We aim to acknowledge reports within 7 days and to ship a fix or mitigation for confirmed high-severity issues as soon as practical. Coordinated disclosure is preferred; please give us a reasonable window before public write-ups.

Scope

In scope: the flow CLI, compiler (src/flow/, compiler/), runtime, stdlib, release/build tooling, and official packages as shipped from this repository.

Security-sensitive compiler/tooling areas include subprocess construction, temporary/build paths, symlink and path traversal handling, imports/includes, archive extraction, package/dependency downloads, plugin loading, hostile-source resource exhaustion, and unsafe FFI boundaries.

Out of scope: third-party packages under registry/ that are not part of a release artifact, and VPS / personal site infrastructure.

Flow 1.0 threat model

The Stable Flow 1.0 compiler must be able to parse, resolve, type-check and lower hostile source without command injection, filesystem traversal or unintended host code execution. Resource-exhaustion and semantic-divergence resistance are qualified separately by the release fuzz programme.

Compiling source and executing source are different trust decisions. flow run deliberately compiles and executes the supplied program with the invoking user's privileges; it is not a sandbox. Likewise, extern, raw pointers and other native FFI facilities are trusted-code boundaries and can perform arbitrary process-visible actions. The local playground/native compile server is development tooling, not a remote multi-tenant execution sandbox.

Surface1.0 security position
Stable compiler pipelineHostile source must not become a shell command, escape permitted import roots, or execute host code merely by being compiled.
Stable subprocessesCompiler/tool invocations use argument vectors rather than shell interpolation. Repository tests reject shell=True, os.system and os.popen under src/flow.
Temporary build stateStable Python tooling uses race-resistant temporary APIs. tempfile.mktemp is forbidden under src/flow.
Module importsStable local resolution stays inside the selected project, stdlib and package roots. Legacy string imports reject absolute, home-relative and parent-traversing paths.
flow runNative execution boundary, not sandboxed. Program exit status is propagated once execution begins.
FFI / externTrusted native boundary, outside safe-source containment guarantees.
Package/dependency acquisitionDependency source and extraction semantics remain Experimental until integrity, symlink and root-containment rules are qualified.
Release artifactsBuilt from a clean checkout, freshness-checked, checksummed, unpacked and exercised before publication. Provenance/signing work is tracked by #652.
Experimental JIT/GPU/hardware pathsDo not inherit the Stable 1.0 security guarantee unless separately promoted.

Release threat review

The release review explicitly covers shell/process injection, import and archive path traversal, temporary-file races, hostile-source crashes or hangs, stale or substituted release artifacts, unsafe native boundaries, and package extraction escapes. New package extraction code promoted to Stable must reject absolute archive members, .. traversal, and symlink-mediated writes outside the package root with regression coverage.

User-supplied compiler/linker flags are an explicit advanced trust boundary: they may intentionally alter compilation, but source text, module names and package metadata must never be implicitly interpolated into shell command strings.

For each release candidate, dependency/static security scans, Stable security invariant tests, self-host qualification and long-fuzz results are reviewed together. A finding is release-severity when it permits unintended host command execution, filesystem escape, artifact substitution, credential disclosure, reliable memory corruption in a Stable compiler/runtime component, or a comparably serious violation of this documented boundary.

Release security gate

Flow 1.0.0 must not ship with a known unresolved critical or high-severity vulnerability in a Stable component. Release qualification also requires the dependency audit and security scans defined in CI, plus disposition of relevant findings from release fuzzing.

Tracking: #650 and the Flow 1.0 stabilisation programme #653.

There aren't any published security advisories

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Security: flooooooooooow/flow

Security

SECURITY.md

Security Policy

Supported Versions

Flow is still on the pre-1.0 development line. Until 1.0.0 ships, only the latest 0.x release line receives fixes.

VersionSupported
0.12.x✅ current pre-1.0 line
< 0.12

When Flow 1.0 ships, the support policy becomes:

VersionSupport
latest 1.x minor✅ bug and security fixes
previous 1.x minor✅ security fixes for 90 days after the next minor release
older 1.x minors
0.x✅ security fixes for 90 days after 1.0.0, then ❌

A security or correctness issue may require an otherwise incompatible change in a supported release when preserving the old behaviour would leave users exposed to a material vulnerability, memory-safety defect, miscompilation, or similarly serious failure. Such changes must be called out prominently in release notes.

Reporting a Vulnerability

Do not open a public GitHub issue for security vulnerabilities.

Please report via one of:

  1. GitHub Security AdvisoriesReport a vulnerability on this repository
  2. Email the maintainer listed on the GitHub org / profile if advisories are unavailable

Include:

  • Affected version / commit
  • Reproduction steps or PoC (as minimal as practical)
  • Impact assessment (RCE, path traversal, sandbox escape, denial of service, etc.)

Response

We aim to acknowledge reports within 7 days and to ship a fix or mitigation for confirmed high-severity issues as soon as practical. Coordinated disclosure is preferred; please give us a reasonable window before public write-ups.

Scope

In scope: the flow CLI, compiler (src/flow/, compiler/), runtime, stdlib, release/build tooling, and official packages as shipped from this repository.

Security-sensitive compiler/tooling areas include subprocess construction, temporary/build paths, symlink and path traversal handling, imports/includes, archive extraction, package/dependency downloads, plugin loading, hostile-source resource exhaustion, and unsafe FFI boundaries.

Out of scope: third-party packages under registry/ that are not part of a release artifact, and VPS / personal site infrastructure.

Flow 1.0 threat model

The Stable Flow 1.0 compiler must be able to parse, resolve, type-check and lower hostile source without command injection, filesystem traversal or unintended host code execution. Resource-exhaustion and semantic-divergence resistance are qualified separately by the release fuzz programme.

Compiling source and executing source are different trust decisions. flow run deliberately compiles and executes the supplied program with the invoking user's privileges; it is not a sandbox. Likewise, extern, raw pointers and other native FFI facilities are trusted-code boundaries and can perform arbitrary process-visible actions. The local playground/native compile server is development tooling, not a remote multi-tenant execution sandbox.

Surface1.0 security position
Stable compiler pipelineHostile source must not become a shell command, escape permitted import roots, or execute host code merely by being compiled.
Stable subprocessesCompiler/tool invocations use argument vectors rather than shell interpolation. Repository tests reject shell=True, os.system and os.popen under src/flow.
Temporary build stateStable Python tooling uses race-resistant temporary APIs. tempfile.mktemp is forbidden under src/flow.
Module importsStable local resolution stays inside the selected project, stdlib and package roots. Legacy string imports reject absolute, home-relative and parent-traversing paths.
flow runNative execution boundary, not sandboxed. Program exit status is propagated once execution begins.
FFI / externTrusted native boundary, outside safe-source containment guarantees.
Package/dependency acquisitionDependency source and extraction semantics remain Experimental until integrity, symlink and root-containment rules are qualified.
Release artifactsBuilt from a clean checkout, freshness-checked, checksummed, unpacked and exercised before publication. Provenance/signing work is tracked by #652.
Experimental JIT/GPU/hardware pathsDo not inherit the Stable 1.0 security guarantee unless separately promoted.

Release threat review

The release review explicitly covers shell/process injection, import and archive path traversal, temporary-file races, hostile-source crashes or hangs, stale or substituted release artifacts, unsafe native boundaries, and package extraction escapes. New package extraction code promoted to Stable must reject absolute archive members, .. traversal, and symlink-mediated writes outside the package root with regression coverage.

User-supplied compiler/linker flags are an explicit advanced trust boundary: they may intentionally alter compilation, but source text, module names and package metadata must never be implicitly interpolated into shell command strings.

For each release candidate, dependency/static security scans, Stable security invariant tests, self-host qualification and long-fuzz results are reviewed together. A finding is release-severity when it permits unintended host command execution, filesystem escape, artifact substitution, credential disclosure, reliable memory corruption in a Stable compiler/runtime component, or a comparably serious violation of this documented boundary.

Release security gate

Flow 1.0.0 must not ship with a known unresolved critical or high-severity vulnerability in a Stable component. Release qualification also requires the dependency audit and security scans defined in CI, plus disposition of relevant findings from release fuzzing.

Tracking: #650 and the Flow 1.0 stabilisation programme #653.

There aren't any published security advisories

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Security: flooooooooooow/flow

Security

SECURITY.md

Security Policy

Supported Versions

Flow is still on the pre-1.0 development line. Until 1.0.0 ships, only the latest 0.x release line receives fixes.

VersionSupported
0.12.x✅ current pre-1.0 line
< 0.12

When Flow 1.0 ships, the support policy becomes:

VersionSupport
latest 1.x minor✅ bug and security fixes
previous 1.x minor✅ security fixes for 90 days after the next minor release
older 1.x minors
0.x✅ security fixes for 90 days after 1.0.0, then ❌

A security or correctness issue may require an otherwise incompatible change in a supported release when preserving the old behaviour would leave users exposed to a material vulnerability, memory-safety defect, miscompilation, or similarly serious failure. Such changes must be called out prominently in release notes.

Reporting a Vulnerability

Do not open a public GitHub issue for security vulnerabilities.

Please report via one of:

  1. GitHub Security AdvisoriesReport a vulnerability on this repository
  2. Email the maintainer listed on the GitHub org / profile if advisories are unavailable

Include:

  • Affected version / commit
  • Reproduction steps or PoC (as minimal as practical)
  • Impact assessment (RCE, path traversal, sandbox escape, denial of service, etc.)

Response

We aim to acknowledge reports within 7 days and to ship a fix or mitigation for confirmed high-severity issues as soon as practical. Coordinated disclosure is preferred; please give us a reasonable window before public write-ups.

Scope

In scope: the flow CLI, compiler (src/flow/, compiler/), runtime, stdlib, release/build tooling, and official packages as shipped from this repository.

Security-sensitive compiler/tooling areas include subprocess construction, temporary/build paths, symlink and path traversal handling, imports/includes, archive extraction, package/dependency downloads, plugin loading, hostile-source resource exhaustion, and unsafe FFI boundaries.

Out of scope: third-party packages under registry/ that are not part of a release artifact, and VPS / personal site infrastructure.

Flow 1.0 threat model

The Stable Flow 1.0 compiler must be able to parse, resolve, type-check and lower hostile source without command injection, filesystem traversal or unintended host code execution. Resource-exhaustion and semantic-divergence resistance are qualified separately by the release fuzz programme.

Compiling source and executing source are different trust decisions. flow run deliberately compiles and executes the supplied program with the invoking user's privileges; it is not a sandbox. Likewise, extern, raw pointers and other native FFI facilities are trusted-code boundaries and can perform arbitrary process-visible actions. The local playground/native compile server is development tooling, not a remote multi-tenant execution sandbox.

Surface1.0 security position
Stable compiler pipelineHostile source must not become a shell command, escape permitted import roots, or execute host code merely by being compiled.
Stable subprocessesCompiler/tool invocations use argument vectors rather than shell interpolation. Repository tests reject shell=True, os.system and os.popen under src/flow.
Temporary build stateStable Python tooling uses race-resistant temporary APIs. tempfile.mktemp is forbidden under src/flow.
Module importsStable local resolution stays inside the selected project, stdlib and package roots. Legacy string imports reject absolute, home-relative and parent-traversing paths.
flow runNative execution boundary, not sandboxed. Program exit status is propagated once execution begins.
FFI / externTrusted native boundary, outside safe-source containment guarantees.
Package/dependency acquisitionDependency source and extraction semantics remain Experimental until integrity, symlink and root-containment rules are qualified.
Release artifactsBuilt from a clean checkout, freshness-checked, checksummed, unpacked and exercised before publication. Provenance/signing work is tracked by #652.
Experimental JIT/GPU/hardware pathsDo not inherit the Stable 1.0 security guarantee unless separately promoted.

Release threat review

The release review explicitly covers shell/process injection, import and archive path traversal, temporary-file races, hostile-source crashes or hangs, stale or substituted release artifacts, unsafe native boundaries, and package extraction escapes. New package extraction code promoted to Stable must reject absolute archive members, .. traversal, and symlink-mediated writes outside the package root with regression coverage.

User-supplied compiler/linker flags are an explicit advanced trust boundary: they may intentionally alter compilation, but source text, module names and package metadata must never be implicitly interpolated into shell command strings.

For each release candidate, dependency/static security scans, Stable security invariant tests, self-host qualification and long-fuzz results are reviewed together. A finding is release-severity when it permits unintended host command execution, filesystem escape, artifact substitution, credential disclosure, reliable memory corruption in a Stable compiler/runtime component, or a comparably serious violation of this documented boundary.

Release security gate

Flow 1.0.0 must not ship with a known unresolved critical or high-severity vulnerability in a Stable component. Release qualification also requires the dependency audit and security scans defined in CI, plus disposition of relevant findings from release fuzzing.

Tracking: #650 and the Flow 1.0 stabilisation programme #653.

There aren't any published security advisories

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Security: flooooooooooow/flow

Security

SECURITY.md

Security Policy

Supported Versions

Flow is still on the pre-1.0 development line. Until 1.0.0 ships, only the latest 0.x release line receives fixes.

VersionSupported
0.12.x✅ current pre-1.0 line
< 0.12

When Flow 1.0 ships, the support policy becomes:

VersionSupport
latest 1.x minor✅ bug and security fixes
previous 1.x minor✅ security fixes for 90 days after the next minor release
older 1.x minors
0.x✅ security fixes for 90 days after 1.0.0, then ❌

A security or correctness issue may require an otherwise incompatible change in a supported release when preserving the old behaviour would leave users exposed to a material vulnerability, memory-safety defect, miscompilation, or similarly serious failure. Such changes must be called out prominently in release notes.

Reporting a Vulnerability

Do not open a public GitHub issue for security vulnerabilities.

Please report via one of:

  1. GitHub Security AdvisoriesReport a vulnerability on this repository
  2. Email the maintainer listed on the GitHub org / profile if advisories are unavailable

Include:

  • Affected version / commit
  • Reproduction steps or PoC (as minimal as practical)
  • Impact assessment (RCE, path traversal, sandbox escape, denial of service, etc.)

Response

We aim to acknowledge reports within 7 days and to ship a fix or mitigation for confirmed high-severity issues as soon as practical. Coordinated disclosure is preferred; please give us a reasonable window before public write-ups.

Scope

In scope: the flow CLI, compiler (src/flow/, compiler/), runtime, stdlib, release/build tooling, and official packages as shipped from this repository.

Security-sensitive compiler/tooling areas include subprocess construction, temporary/build paths, symlink and path traversal handling, imports/includes, archive extraction, package/dependency downloads, plugin loading, hostile-source resource exhaustion, and unsafe FFI boundaries.

Out of scope: third-party packages under registry/ that are not part of a release artifact, and VPS / personal site infrastructure.

Flow 1.0 threat model

The Stable Flow 1.0 compiler must be able to parse, resolve, type-check and lower hostile source without command injection, filesystem traversal or unintended host code execution. Resource-exhaustion and semantic-divergence resistance are qualified separately by the release fuzz programme.

Compiling source and executing source are different trust decisions. flow run deliberately compiles and executes the supplied program with the invoking user's privileges; it is not a sandbox. Likewise, extern, raw pointers and other native FFI facilities are trusted-code boundaries and can perform arbitrary process-visible actions. The local playground/native compile server is development tooling, not a remote multi-tenant execution sandbox.

Surface1.0 security position
Stable compiler pipelineHostile source must not become a shell command, escape permitted import roots, or execute host code merely by being compiled.
Stable subprocessesCompiler/tool invocations use argument vectors rather than shell interpolation. Repository tests reject shell=True, os.system and os.popen under src/flow.
Temporary build stateStable Python tooling uses race-resistant temporary APIs. tempfile.mktemp is forbidden under src/flow.
Module importsStable local resolution stays inside the selected project, stdlib and package roots. Legacy string imports reject absolute, home-relative and parent-traversing paths.
flow runNative execution boundary, not sandboxed. Program exit status is propagated once execution begins.
FFI / externTrusted native boundary, outside safe-source containment guarantees.
Package/dependency acquisitionDependency source and extraction semantics remain Experimental until integrity, symlink and root-containment rules are qualified.
Release artifactsBuilt from a clean checkout, freshness-checked, checksummed, unpacked and exercised before publication. Provenance/signing work is tracked by #652.
Experimental JIT/GPU/hardware pathsDo not inherit the Stable 1.0 security guarantee unless separately promoted.

Release threat review

The release review explicitly covers shell/process injection, import and archive path traversal, temporary-file races, hostile-source crashes or hangs, stale or substituted release artifacts, unsafe native boundaries, and package extraction escapes. New package extraction code promoted to Stable must reject absolute archive members, .. traversal, and symlink-mediated writes outside the package root with regression coverage.

User-supplied compiler/linker flags are an explicit advanced trust boundary: they may intentionally alter compilation, but source text, module names and package metadata must never be implicitly interpolated into shell command strings.

For each release candidate, dependency/static security scans, Stable security invariant tests, self-host qualification and long-fuzz results are reviewed together. A finding is release-severity when it permits unintended host command execution, filesystem escape, artifact substitution, credential disclosure, reliable memory corruption in a Stable compiler/runtime component, or a comparably serious violation of this documented boundary.

Release security gate

Flow 1.0.0 must not ship with a known unresolved critical or high-severity vulnerability in a Stable component. Release qualification also requires the dependency audit and security scans defined in CI, plus disposition of relevant findings from release fuzzing.

Tracking: #650 and the Flow 1.0 stabilisation programme #653.

There aren't any published security advisories

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Security: flooooooooooow/flow

Security

SECURITY.md

Security Policy

Supported Versions

Flow is still on the pre-1.0 development line. Until 1.0.0 ships, only the latest 0.x release line receives fixes.

VersionSupported
0.12.x✅ current pre-1.0 line
< 0.12

When Flow 1.0 ships, the support policy becomes:

VersionSupport
latest 1.x minor✅ bug and security fixes
previous 1.x minor✅ security fixes for 90 days after the next minor release
older 1.x minors
0.x✅ security fixes for 90 days after 1.0.0, then ❌

A security or correctness issue may require an otherwise incompatible change in a supported release when preserving the old behaviour would leave users exposed to a material vulnerability, memory-safety defect, miscompilation, or similarly serious failure. Such changes must be called out prominently in release notes.

Reporting a Vulnerability

Do not open a public GitHub issue for security vulnerabilities.

Please report via one of:

  1. GitHub Security AdvisoriesReport a vulnerability on this repository
  2. Email the maintainer listed on the GitHub org / profile if advisories are unavailable

Include:

  • Affected version / commit
  • Reproduction steps or PoC (as minimal as practical)
  • Impact assessment (RCE, path traversal, sandbox escape, denial of service, etc.)

Response

We aim to acknowledge reports within 7 days and to ship a fix or mitigation for confirmed high-severity issues as soon as practical. Coordinated disclosure is preferred; please give us a reasonable window before public write-ups.

Scope

In scope: the flow CLI, compiler (src/flow/, compiler/), runtime, stdlib, release/build tooling, and official packages as shipped from this repository.

Security-sensitive compiler/tooling areas include subprocess construction, temporary/build paths, symlink and path traversal handling, imports/includes, archive extraction, package/dependency downloads, plugin loading, hostile-source resource exhaustion, and unsafe FFI boundaries.

Out of scope: third-party packages under registry/ that are not part of a release artifact, and VPS / personal site infrastructure.

Flow 1.0 threat model

The Stable Flow 1.0 compiler must be able to parse, resolve, type-check and lower hostile source without command injection, filesystem traversal or unintended host code execution. Resource-exhaustion and semantic-divergence resistance are qualified separately by the release fuzz programme.

Compiling source and executing source are different trust decisions. flow run deliberately compiles and executes the supplied program with the invoking user's privileges; it is not a sandbox. Likewise, extern, raw pointers and other native FFI facilities are trusted-code boundaries and can perform arbitrary process-visible actions. The local playground/native compile server is development tooling, not a remote multi-tenant execution sandbox.

Surface1.0 security position
Stable compiler pipelineHostile source must not become a shell command, escape permitted import roots, or execute host code merely by being compiled.
Stable subprocessesCompiler/tool invocations use argument vectors rather than shell interpolation. Repository tests reject shell=True, os.system and os.popen under src/flow.
Temporary build stateStable Python tooling uses race-resistant temporary APIs. tempfile.mktemp is forbidden under src/flow.
Module importsStable local resolution stays inside the selected project, stdlib and package roots. Legacy string imports reject absolute, home-relative and parent-traversing paths.
flow runNative execution boundary, not sandboxed. Program exit status is propagated once execution begins.
FFI / externTrusted native boundary, outside safe-source containment guarantees.
Package/dependency acquisitionDependency source and extraction semantics remain Experimental until integrity, symlink and root-containment rules are qualified.
Release artifactsBuilt from a clean checkout, freshness-checked, checksummed, unpacked and exercised before publication. Provenance/signing work is tracked by #652.
Experimental JIT/GPU/hardware pathsDo not inherit the Stable 1.0 security guarantee unless separately promoted.

Release threat review

The release review explicitly covers shell/process injection, import and archive path traversal, temporary-file races, hostile-source crashes or hangs, stale or substituted release artifacts, unsafe native boundaries, and package extraction escapes. New package extraction code promoted to Stable must reject absolute archive members, .. traversal, and symlink-mediated writes outside the package root with regression coverage.

User-supplied compiler/linker flags are an explicit advanced trust boundary: they may intentionally alter compilation, but source text, module names and package metadata must never be implicitly interpolated into shell command strings.

For each release candidate, dependency/static security scans, Stable security invariant tests, self-host qualification and long-fuzz results are reviewed together. A finding is release-severity when it permits unintended host command execution, filesystem escape, artifact substitution, credential disclosure, reliable memory corruption in a Stable compiler/runtime component, or a comparably serious violation of this documented boundary.

Release security gate

Flow 1.0.0 must not ship with a known unresolved critical or high-severity vulnerability in a Stable component. Release qualification also requires the dependency audit and security scans defined in CI, plus disposition of relevant findings from release fuzzing.

Tracking: #650 and the Flow 1.0 stabilisation programme #653.

There aren't any published security advisories