Skip to content
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
15 changes: 10 additions & 5 deletions SECURITY.md
Original file line number Diff line number Diff line change
Expand Up @@ -4,18 +4,21 @@ Deployment config for a shared PostgreSQL instance pinned to a stable Alpine tag

## Supported versions

Only the current `main` branch is supported. Fixes land on `main`; there are no release branches.
Only the current `main` branch is supported.
Fixes land on `main`; there are no release branches.

## Reporting a vulnerability

Please report privately. Do not open a public issue or pull request.
Please report privately.
Do not open a public issue or pull request.

- **Preferred:** [report a vulnerability](https://github.com/JOduMonT/postgresql/security/advisories/new) through GitHub private vulnerability reporting.
- **Email:** jodumont+security@gmail.com
- Include what you found, the affected file or service, steps to reproduce and the impact you see.
- Do not access, change or delete data that is not yours, and do not run denial-of-service or automated scanning against live systems.

You can expect an acknowledgement within 3 business days and a status update within 10. Confirmed issues are fixed as quickly as severity allows, and you are credited in the fix unless you prefer not to be.
You can expect an acknowledgement within 3 business days and a status update within 10.
Confirmed issues are fixed as quickly as severity allows, and you are credited in the fix unless you prefer not to be.

## Scope

Expand All @@ -30,8 +33,10 @@ Out of scope:

## How this repository is kept safe

- Dependabot alerts and security updates are on; a vulnerable dependency gets an automatic pull request. Routine version bumps are opened by Renovate, and `.github/dependabot.yml` keeps Dependabot's own version updates off to avoid duplicate pull requests.
- Dependabot pull requests are merged automatically by `.github/workflows/dependabot-auto-merge.yml` once every other check passes. Major version bumps are left open for review.
- Dependabot alerts and security updates are on; a vulnerable dependency gets an automatic pull request.
Routine version bumps are opened by Renovate, and `.github/dependabot.yml` keeps Dependabot's own version updates off to avoid duplicate pull requests.
- Dependabot pull requests are merged automatically by `.github/workflows/dependabot-auto-merge.yml` once every other check passes.
Major version bumps are left open for review.
- GitHub secret scanning with push protection and CodeQL code scanning are enabled.
- Credentials are injected by Coolify or `.env`, never committed; keep the instance internal-only.
- Image bumps come from Renovate and are smoke-tested in CI; a major upgrade is a dump and restore, done by hand.
Loading