| Version | Supported |
|---|---|
| 1.0.x | Yes |
| < 1.0 | No |
We take security seriously. If you discover a security vulnerability, please report it responsibly.
Do not open a public issue for security vulnerabilities.
Instead, please use GitHub's private vulnerability reporting:
- Go to the Security tab of this repository
- Click "Report a vulnerability"
- Provide a detailed description of the vulnerability
- Description of the vulnerability
- Steps to reproduce
- Potential impact
- Suggested fix (if any)
- Acknowledgment: Within 48 hours
- Initial assessment: Within 1 week
- Resolution: Depends on severity and complexity
This utility:
- Runs with elevated privileges during installation (sudo required)
- Manages server configuration files with sensitive data (admin secrets)
- Executes shell commands based on user input
- Configuration file permissions enforced (mode 600)
- Config key validation prevents injection attacks
- Installation directory validated before destructive operations
- Warnings displayed for world-readable config files
- Default admin secret must be changed before use
We follow responsible disclosure practices. Once a fix is available, we will:
- Release the patched version
- Update the changelog with security notes
- Credit the reporter (unless they prefer anonymity)