Report suspected vulnerabilities privately using this repository's Security → Report a vulnerability (private vulnerability reporting). Do not open a public issue for a suspected vulnerability.
This repository ships a static frontend for Apache Guacamole 1.6.0. The
Guacamole backend, guacd, the database and any reverse proxy are stock
upstream components or operator-provided infrastructure; report upstream
issues to the Apache Guacamole project (https://guacamole.apache.org/security/).
The staging/ directory is disposable test infrastructure only and is not a
production deployment recommendation. Its pinned historical container
images carry nonzero package-scan findings; production operators must select
patched images, review the applicability of materially applicable findings
and validate their own deployment.
Security fixes, when needed, are published in a new release of this
repository. The supported configurations, authentication providers and
compatibility exclusions are stated in
docs/STABLE-SCOPE.md; the acceptance record and
known deviations are in docs/STABLE-ACCEPTANCE.md
and docs/DELIVERY.md.
- The shipped dependency set is covered by
npm audit(zero findings at the recorded acceptance run). - The release archive excludes
.git,node_modules, caches, staging.envfiles, TLS private keys and the private evidence bundle. - Acceptance evidence is sanitized: network captures redact credentials, and TOTP secrets, codes and QR images are never exported.