Report a suspected vulnerability through GitHub Security Advisories for this repository. Do not open a public issue for a security defect.
Include these details:
- Affected Bifrost version
- Deployment role
- System architecture
- Minimal configuration with all secrets removed
- Reproduction steps
- Expected impact
Do not include live credentials, public service addresses, or edge keys. You should receive an acknowledgment within seven days.
Security fixes support the latest released minor version. Before the first v1 release, only the current main branch is supported.
Use the private channel for a report about DNS ownership bypass, unauthenticated edge metadata, unsafe edge destination resolution, secret disclosure, or privilege-boundary escape.
Use a public discussion for an operational question or a configuration error that does not expose sensitive information.