Security

Your code never leaves your machine.

FLY8HT runs other people's code on your computer, so we treat that seriously. Here's the model, what we've hardened, what's still open, and how to tell us about a problem.

Local-first by designNo FLY8HT servers hold your dataEncrypted secrets

Scope

What this covers.

No active advisories

There are no open security advisories for FLY8HT. Fixes ship through the built-in auto-updater.

In scope

The FLY8HT desktop app on every platform, its published installers and updater, and this website.

Out of scope

The projects you choose to run. FLY8HT isolates them as well as it can, but it doesn’t audit third-party code for you.

Security model

Layers between a repository and your system.

Local-first

Projects, builds, logs and settings live in a SQLite file on your disk. There’s no FLY8HT server to breach.

Sandboxed UI

The interface has context isolation on, Node integration off, and talks to the system only through named actions.

Validated twice

Every request from the interface is re-validated against a strict schema in the trusted main process.

Isolated builds

Docker builds run non-root with process and memory limits, no-new-privileges, and only the project folder mounted.

Encrypted secrets

Environment variables and GitHub tokens are encrypted with your operating system’s own secure storage.

Redacted logs

Every configured variable’s value is stripped from build and runtime logs before they’re stored or shown.

Safe commands

Manually-typed commands go through an executable allowlist and reject shell operators like ; | && and $().

Contained paths

Every path a project supplies is resolved and checked against its own workspace before FLY8HT touches it.

Hardening we've shipped

Real issues, found and fixed.

Most of these were found by running real repositories and reading real logs, not assumed from code review.

Containers

Stopped the host's HOME and other machine-identity variables leaking into build containers.

Private repos

Git credentials are sent as a one-shot header per command, never written to a git config or remote URL.

URL validation

GitHub URLs must use http(s). A file:// URL with a github.com hostname is rejected outright.

Paths

The workspace containment check uses the platform's own path separator, so it holds on Windows too.

Processes

A PID is only ever signalled after confirming its command line matches what FLY8HT launched.

Project removal

Removing a project stops its running app first, so nothing is left orphaned on a port.

Git safety

Branch switches and pulls refuse to run over uncommitted changes, and no force option exists.

Branch names

Names starting with -, containing .. or shell metacharacters are rejected before reaching git.

Known gaps

What isn't done yet, stated plainly.

  • Windows and Linux are verified by automated CI builds and tests, not yet by daily use on real hardware.
  • Readiness is checked with a TCP connection, not an HTTP request, so a slow app can briefly look ready early.
  • Multi-container docker-compose projects are parsed for information but not isolated or run.
  • IPC inputs are schema-validated, but haven't been fuzzed beyond that.

Report a vulnerability

Tell us before anyone else.

Email support@fly8ht.app. We'll acknowledge genuine reports, work on a real fix, and credit you once it's resolved if you'd like.

  • Include the FLY8HT version and your operating system.
  • Give exact steps to reproduce. A minimal repository helps a lot.
  • Describe the impact: what could an attacker actually do?
  • Please don't disclose publicly until we've had a reasonable chance to fix it.
  • We don't run a paid bug bounty today.
Report template
Summary:        one line describing the issue
Affected:       desktop app / website, version (Settings → General)
OS:             macOS / Windows / Linux + version
Steps:          1. …  2. …  3. …
Impact:         what an attacker could do
Suggested fix:  optional

Questions about how FLY8HT handles data?

The privacy statement covers exactly what the app and website store.