Skip to content

Security: CruxExperts/BestBackup

SECURITY.md

Security policy

This policy covers security issues in bbackup's source code and the packaged commands.

Version status

The current stable legacy package version is 1.8.6. Version 2.0.0-alpha.1 is a pre-release; the version 2 operations interface remains a preview and is not production-qualified. Security reports for preview code are still welcome through the private reporting process below.

Security fixes are prepared for the latest published release. The project does not promise backports to older versions.

Report a vulnerability

Do not post security vulnerabilities in a public issue. Use GitHub's private vulnerability reporting and include the affected version or commit, impact, and a safe reproduction when available. Redact secrets and customer data. The maintainers will acknowledge reports within five business days and coordinate any public disclosure with the reporter.

Scope

This policy covers bbackup's first-party code. It does not provide security support for the host operating system, restic, Docker, database servers, or third-party cloud providers and services.

Do not commit encryption keys, restic passwords, cloud credentials, tokens, host bindings, backup archives, or unredacted production configuration. Private files should have owner-only access. Keep independently recoverable copies of repository passwords and recovery-kit keys outside the host being protected.



Slavic Kozyuk
© 2026 Crux Experts LLC — MIT License

There aren't any published security advisories