Security

Security.

Report a vulnerability

Use GitHub private vulnerability reporting, as described in SECURITY.md. Do not open a public issue, discussion or pull request for a vulnerability.

SECURITY.md also sets out what to expect: an acknowledgement within 7 days, an initial assessment within 14 days, and which reports are in scope.

What CloudBurrow is not

CloudBurrow is a local emulator for development and testing. These are documented properties, not bugs:

Supply chain

Each release archive has a SHA-256 checksum and a GitHub build attestation; the install script refuses an archive it cannot verify. docs/install.md

Found a vulnerability?

Report it privately. The report is visible only to you and the maintainers.

Get started