Scope
What this covers.
There are no open security advisories for FLY8HT. Fixes ship through the built-in auto-updater.
In scope
The FLY8HT desktop app on every platform, its published installers and updater, and this website.
Out of scope
The projects you choose to run. FLY8HT isolates them as well as it can, but it doesn’t audit third-party code for you.
Security model
Layers between a repository and your system.
Local-first
Sandboxed UI
Validated twice
Isolated builds
Encrypted secrets
Redacted logs
Safe commands
Contained paths
Hardening we've shipped
Real issues, found and fixed.
Most of these were found by running real repositories and reading real logs, not assumed from code review.
Containers
Stopped the host's HOME and other machine-identity variables leaking into build containers.
Private repos
Git credentials are sent as a one-shot header per command, never written to a git config or remote URL.
URL validation
GitHub URLs must use http(s). A file:// URL with a github.com hostname is rejected outright.
Paths
The workspace containment check uses the platform's own path separator, so it holds on Windows too.
Processes
A PID is only ever signalled after confirming its command line matches what FLY8HT launched.
Project removal
Removing a project stops its running app first, so nothing is left orphaned on a port.
Git safety
Branch switches and pulls refuse to run over uncommitted changes, and no force option exists.
Branch names
Names starting with -, containing .. or shell metacharacters are rejected before reaching git.
Known gaps
What isn't done yet, stated plainly.
- Windows and Linux are verified by automated CI builds and tests, not yet by daily use on real hardware.
- Readiness is checked with a TCP connection, not an HTTP request, so a slow app can briefly look ready early.
- Multi-container docker-compose projects are parsed for information but not isolated or run.
- IPC inputs are schema-validated, but haven't been fuzzed beyond that.
Report a vulnerability
Tell us before anyone else.
Email support@fly8ht.app. We'll acknowledge genuine reports, work on a real fix, and credit you once it's resolved if you'd like.
- Include the FLY8HT version and your operating system.
- Give exact steps to reproduce. A minimal repository helps a lot.
- Describe the impact: what could an attacker actually do?
- Please don't disclose publicly until we've had a reasonable chance to fix it.
- We don't run a paid bug bounty today.
Summary: one line describing the issue Affected: desktop app / website, version (Settings → General) OS: macOS / Windows / Linux + version Steps: 1. … 2. … 3. … Impact: what an attacker could do Suggested fix: optional
Questions about how FLY8HT handles data?
The privacy statement covers exactly what the app and website store.