Developers

Security Policy

Supported versions and the private GitHub channel for reporting a vulnerability.

NasDash SECURITY.md supports the latest published 0.1.x release and main. The deleted v1.0.0 tag is not a supported version.

VersionSupport status
Current main branchsupported
Latest published 0.1.x releasesupported
Older releasesbest effort; an upgrade may be required
Third-party forks or unofficial imagesnot supported

Reporting a vulnerability

Use the GitHub private advisory form. Do not contact the maintainer by personal email.

If private reporting is not available, open a minimal issue asking for a private contact channel. Do not include exploit code, credentials, tokens, private URLs, configuration files or other sensitive details in a public issue.

Include, when possible:

  • the affected NasDash version, image tag or commit;
  • the deployment method and relevant environment details;
  • clear reproduction steps and the security impact;
  • sanitized logs, requests or a minimal proof of concept.

You should receive an acknowledgement within seven days and an initial assessment within fourteen days.

Do not test a vulnerability against an instance you do not own or without explicit authorization.

The reference text remains SECURITY.md.