Skip to content

Security policy

Firefly Weave is an alpha project. The capability matrix describes current verification and limitations. No supported stable-release or security-response SLA is announced by this source tree.

Reporting a concern

Do not post credentials, private data or exploit details in a public issue. Use GitHub private vulnerability reporting to send a report privately to the repository maintainers. The package author address is not a designated security response mailbox.

Prepare a minimal, redacted report with the affected source/package version, the component (API, native executor, worker, CLI, Studio host, desktop app, or Studio page), configuration and trust boundary, reproduction steps against an owned fixture, expected/observed behavior and impact. Use synthetic values and redact tokens, connection strings, provider payloads, user data and local secret paths.

Verified identity, local grants, and scoped secret resolution

How to read this diagram: Each numbered question must pass before the next one is asked. Use them to name the boundary your report affects: a verified token, a local permission, and a connector secret serve different roles.

Open diagram at full size

Deployment boundaries

Use verified identity links and local scoped grants, separate migration/app/worker credentials, explicit secret references, TLS and allowed-destination policies. Never place secrets in workflow literals or ordinary outputs. Tenant RLS is one layer alongside service authorization, not a replacement for it. Live-provider, production restore/upgrade and operational guarantees require their own evidence. See identity and secrets and configuration.

On people's computers, the CLI, Studio, and the desktop app keep tokens in the operating system's credential store or in a private file the person chooses, never in the saved platforms file or the Studio browser page. In the current source, planned for the next release, the public GET /api/v1/client-configuration endpoint publishes sign-in settings only; its contract cannot carry a client secret, token, or verifier configuration. See what is saved, and where.