| Version | Supported |
|---|---|
| main | ✅ Yes |
| develop | ✅ Yes |
| < 1.0 |
Please do NOT file public GitHub issues for security vulnerabilities.
Use GitHub Security Advisories to report vulnerabilities privately.
Include:
- Description of the vulnerability
- Steps to reproduce
- Potential impact
- Suggested fix (if any)
We aim to acknowledge reports within 48 hours and provide a fix or mitigation within 90 days.
We follow Coordinated Vulnerability Disclosure (CVD).
- Never commit private keys to the repository — use the scripts in
keys/to generate them offline. - Verify image signatures before flashing using RAUC's bundle verification.
- Enable TPM measured boot to detect unauthorized firmware modifications.
- Rotate RAUC signing keys periodically and revoke compromised keys.
- Keep components updated — subscribe to security advisories for this repo.