Skip to content

Security: SovNodeAI/guacamole-angular-port

Security

SECURITY.md

Security policy

Reporting a vulnerability

Report suspected vulnerabilities privately using this repository's Security → Report a vulnerability (private vulnerability reporting). Do not open a public issue for a suspected vulnerability.

Scope of this repository

This repository ships a static frontend for Apache Guacamole 1.6.0. The Guacamole backend, guacd, the database and any reverse proxy are stock upstream components or operator-provided infrastructure; report upstream issues to the Apache Guacamole project (https://guacamole.apache.org/security/).

The staging/ directory is disposable test infrastructure only and is not a production deployment recommendation. Its pinned historical container images carry nonzero package-scan findings; production operators must select patched images, review the applicability of materially applicable findings and validate their own deployment.

Supported scope

Security fixes, when needed, are published in a new release of this repository. The supported configurations, authentication providers and compatibility exclusions are stated in docs/STABLE-SCOPE.md; the acceptance record and known deviations are in docs/STABLE-ACCEPTANCE.md and docs/DELIVERY.md.

Dependency and secret hygiene

  • The shipped dependency set is covered by npm audit (zero findings at the recorded acceptance run).
  • The release archive excludes .git, node_modules, caches, staging .env files, TLS private keys and the private evidence bundle.
  • Acceptance evidence is sanitized: network captures redact credentials, and TOTP secrets, codes and QR images are never exported.

There aren't any published security advisories