This policy covers security issues in bbackup's source code and the packaged commands.
The current stable legacy package version is 1.8.6. Version 2.0.0-alpha.1 is a pre-release; the version 2 operations interface remains a preview and is not production-qualified. Security reports for preview code are still welcome through the private reporting process below.
Security fixes are prepared for the latest published release. The project does not promise backports to older versions.
Do not post security vulnerabilities in a public issue. Use GitHub's private vulnerability reporting and include the affected version or commit, impact, and a safe reproduction when available. Redact secrets and customer data. The maintainers will acknowledge reports within five business days and coordinate any public disclosure with the reporter.
This policy covers bbackup's first-party code. It does not provide security support for the host operating system, restic, Docker, database servers, or third-party cloud providers and services.
Do not commit encryption keys, restic passwords, cloud credentials, tokens, host bindings, backup archives, or unredacted production configuration. Private files should have owner-only access. Keep independently recoverable copies of repository passwords and recovery-kit keys outside the host being protected.
Slavic Kozyuk
© 2026 Crux Experts LLC — MIT License