Security fixes are provided for the current major release only.
| Version | Supported |
|---|---|
| 4.x | Yes |
| 3.x and earlier | No |
Users on unsupported versions should upgrade before requesting a security fix.
Do not open a public issue, discussion, or pull request for a suspected vulnerability.
Use GitHub's private vulnerability reporting and include:
- the affected package and Flutter versions;
- affected platforms and configurations;
- a description of the impact and realistic attack scenario;
- minimal reproduction steps or a proof of concept;
- any known mitigations or suggested remediation;
- whether the vulnerability has been disclosed elsewhere.
Maintainers aim to acknowledge reports within seven calendar days and provide an initial assessment within fourteen calendar days. Timelines depend on severity and reproducibility. Reporters will receive updates through the private advisory until remediation and coordinated disclosure are complete.
Ordinary crashes, visual defects, and usage questions are not security vulnerabilities; report those through the appropriate issue form or Discussion.