Skip to content

Security: kkir/stomatopod

Security

SECURITY.md

Security policy

Supported versions

Security fixes are applied on the default branch (main). There is no long-term stable branch yet; please upgrade to the latest commit or release tag.

Reporting a vulnerability

Please do not open a public GitHub issue for security problems.

Report privately via one of:

Include steps to reproduce, impact, and any suggested fix. You can expect an acknowledgement when the report is received; timelines depend on severity and maintainer availability.

Scope notes

  • Self-hosted deployments must set a strong auth.secret_key, admin password, and STOMATOPOD_ADMIN_EMAIL; do not expose an unconfigured instance to the public internet.
  • Optional MaxMind GeoLite databases are supplied by the operator; their license terms are separate from this project.

There aren't any published security advisories