Skip to content

Security: lanbat/nixos

SECURITY.md

Security policy

This repository configures a live homelab, so please report vulnerabilities privately rather than in public issues or pull requests.

Reporting a vulnerability

Use GitHub's private vulnerability reporting: open the Security tab and choose Report a vulnerability, or go straight to https://github.com/lanbat/nixos/security/advisories/new.

Include the affected files or services, what an attacker could do, and how to reproduce it if you can.

What to expect

This is a personal project maintained on a best-effort basis. You will get an acknowledgement once the report is seen, and a fix or an explanation afterwards.

Scope

In scope: anything in this repository (NixOS modules, service configuration, scripts and CI). Report bugs in upstream software, such as NixOS, nixpkgs packages or the container images used here, to those projects.

There aren't any published security advisories