| Version | Supported |
|---|---|
| 2.1.x | ✅ |
| < 2.1 | ❌ — upgrade to the latest 2.1.x (2.0.x lets the All scope delete across tenants; 1.x feeds can skip records — see the changelog) |
Papuma Kernel has not yet carried production traffic (see Maturity). Fixes land on the current minor version; there are no backports.
Please do not open a public issue.
Use GitHub's private vulnerability reporting on this repository (Security → Report a vulnerability), which opens a private advisory visible only to the maintainer.
What helps:
- the affected package and version,
- what an attacker gains (read across tenants, bypass a privacy policy, …),
- a minimal reproduction — ideally a failing test against the real engine.
You can expect an acknowledgement within a few days, an assessment with a severity and a planned fix window after triage, and credit in the advisory and the changelog unless you prefer otherwise. Please give a fix a reasonable chance to ship before disclosing publicly.
These are the parts where a bug is a vulnerability rather than a defect:
- Scope and tenant isolation —
ScopeContext, the explicitscope/tenant_idpredicates, and the PostgreSQL row-level security policies behind them (ADR-001, architecture). - Privacy policies — the five-tier catalog applied at write time, before anything reaches the immutable change feed (ADR-007).
- GDPR tooling — history redaction, masked reads, export assembly (gdpr.md, ADR-015).
- Schema and identifier handling — the DDL identifier validator on the startup schema path.
- The ASP.NET Core dashboard — it is unauthenticated unless you put authorization in front of it; mapping it without authorization metadata emits a startup warning. Exposing it publicly is a deployment mistake, not a kernel vulnerability.
- Findings that require an already-compromised database superuser.
- Denial of service by unbounded application input that the application itself is expected to bound.
- Missing hardening in
samples/— samples are illustrative, not deployable.