| FazBrowse GitHub Viewer | Trending | | Home |
| Tools: [Download Repo ZIP] [Original HTTPS Page] |
Betaflight is an open-source project maintained by volunteers. We take the security of the firmware, the app and supporting services seriously, and we appreciate the efforts of security researchers and users who report issues responsibly.
This is the canonical security policy for all Betaflight repositories. Individual repositories may link here rather than duplicating it.
Please do not report security vulnerabilities through public GitHub issues, pull requests, Discord, or any other public channel. Public disclosure before a fix is available puts users at risk.
Instead, use one of the private channels below.
Many Betaflight repositories have GitHub's private vulnerability reporting enabled. Where it is available:
This keeps the report private to the maintainers and lets us collaborate with you on a fix and a coordinated advisory.
If private reporting is not enabled on the repository, you cannot use GitHub, or your report concerns infrastructure rather than a specific repository, email:
Email always works as a fallback, regardless of which repository is affected.
If you wish to encrypt your report, ask us for a current PGP key in an initial (unencrypted) message containing no sensitive details.
A good report helps us triage quickly. Where possible, please include:
This policy covers the projects maintained under the Betaflight organisation, including but not limited to:
The following are generally not treated as Betaflight vulnerabilities. Report them upstream where applicable:
If you are unsure whether something is in scope, report it anyway and let us decide.
As a volunteer project, we cannot guarantee fixed response times, but we aim to:
We will publish a GitHub Security Advisory for confirmed vulnerabilities once a fix or mitigation is available.
With your permission, we are happy to credit you in the security advisory and release notes for responsibly disclosed vulnerabilities. Let us know how you would like to be named, or if you prefer to remain anonymous.
Betaflight does not currently operate a paid bug bounty programme.
We consider security research and vulnerability disclosure conducted in good faith and in accordance with this policy to be authorised. We will not pursue or support legal action against researchers who:
If in doubt about whether an action is acceptable, contact us first at security@betaflight.com.
| Back | FazBrowse Home | New Git URL |