We recommend using the latest released version. Only the most recent release receives security patches.
This service is designed for internal deployment behind Flare's infrastructure. It is not intended to be exposed directly to the public internet. Access is controlled via API key authentication (X-API-KEY header).
Please do not report a vulnerability using an issue or any other public channel.
To disclose a vulnerability, reach out to any of the codeowners.
Critical vulnerabilities will be disclosed via GitHub's security advisory system.
Audit reports are published on Flare's Developer Hub. The full audit scope is listed in CONTRIBUTING.md.