Security

Deplo runs other people's infrastructure, so please do not report a vulnerability in a public issue, a discussion, or a pull request: a public report is a live map for anyone reading it before the fix ships.

Reporting a vulnerability

Preferred: open a private security advisory at github.com/DeploCloud/deplo/security/advisories/new. It is private to you and the maintainers, it keeps the whole conversation and the fix in one place, and it is what assigns a CVE and credits you when the advisory is published. No GitHub account? Email [email protected]. If you want to encrypt the report, say so in a first message and we will send you a key. A useful report has the version of Deplo, what an attacker gains, and the shortest path you know to reproduce it. A working proof of concept is welcome but never required.

What to expect

Acknowledgement: within 72 hours. Assessment and severity: within 7 days. Coordinated disclosure: within 90 days of the report, or as soon as a fix ships. If a report turns out not to be a vulnerability, you get that answer with the reasoning, not silence. We publish a GitHub Security Advisory for every confirmed vulnerability and credit the reporter by the name they ask for. Tell us if you would rather stay anonymous.

While you are testing

Test against your own installation. Deplo installs in one command on any server you control, so there is never a reason to probe someone else's. Do not access, modify or keep data that is not yours. If you land on real user data, stop there and say so in the report. Keep the finding between you and the maintainers until the fix ships, or 90 days from the report, whichever comes first.

Supported versions

Only the latest minor release receives security fixes, which today means 0.x. Deplo checks for newer releases and tells you in the dashboard, so staying current is the supported path.

In scope

The control plane: authentication, the authorization boundary, the GraphQL API, the MCP server, and the REST routes under /api. The server agent and the mTLS PKI that fronts it. Compose and Traefik rendering, including any way a team member can reach the host or another team's data through authored compose. Secret handling: encryption at rest, the deploy edge, backup artifacts. The install.sh, install-agent.sh and uninstall.sh scripts.

Out of scope

Applications a user deploys with Deplo, and the images they pull. Deplo runs them, it does not vouch for them. A user's own DNS, firewall, or server hardening. Third-party images in the template catalog. Report those upstream. Findings that require a capability the actor already legitimately holds. Someone granted canMountHostVolumes is expected to be able to reach the host, that is what the grant means. A way to reach the host without it is very much in scope. Volumetric denial of service, missing security headers with no exploit path, and automated scanner output with no demonstrated impact.

No bug bounty

Deplo does not run a paid bounty program and cannot pay for reports. What we offer is a fast, honest answer, a credited advisory, and the fix shipped to every install.

The machine-readable version of this page is at /.well-known/security.txt, and the same policy ships as SECURITY.md in the repository.