Skip to content

Security: epheo/dotvirt

Security

SECURITY.md

Security Policy

Reporting a vulnerability

Please report security issues privately — do not open a public issue for an unfixed vulnerability.

You can expect an acknowledgement within a few days. Once a fix is available it is released as a new digest-pinned version (see hack/release.sh) and, where relevant, a GitHub Security Advisory.

Scope

dotvirt's runtime owns nothing: it reads git/cluster/Argo and proposes pull requests, riding the calling user's RBAC. The privileged install RBAC and the forge-admin credential live only in the operator (install-time), kept distinct from the app's narrow clone/push token. Reports that concern privilege boundaries between these two identities, the user-token pass-through, or the GitOps PR-merge gate are especially welcome.

Supported versions

Only the latest released version is supported. dotvirt is pre-1.0 (v1alpha1); fixes land on main and in the next release.

There aren't any published security advisories