| Version | Supported |
|---|---|
1.0.0 |
✅ fixes land on main |
Please report privately rather than in a public issue, so a fix can ship before the details are widely known.
Use GitHub's private vulnerability reporting,
or email opensource@epignosishq.com with Security: flipster in the subject.
Please include the affected version, your PHP version, and a reproduction if you have one. We will acknowledge within five working days and keep you updated as we work on it. If you would like credit in the advisory, say so and how you would like to be named.
Two aspects of this library are security-relevant in ways that are easy to miss:
Flag values reach logs. Flipster logs a warning every time a declared default is served, including the flag key. Flag values are not logged, but flag keys are — avoid encoding secrets in key names.
A degraded provider serves declared defaults. That is the point of the library, but it means an attacker who can make your flag backend unreachable can force every flag to its declared value. If a flag gates access to something sensitive, declare the safe value — usually the restrictive one — not the convenient one.
PHP 8.1 is end-of-life and receives no security fixes from the PHP project. Flipster supports it so it can be adopted by codebases mid-migration; that support is not a suggestion that running 8.1 is safe.