Skip to content

Security: zwall-net/zwall-community

SECURITY.md

Security Policy

Reporting a Vulnerability

Do not report security vulnerabilities in public issues, pull requests, or discussions.

For the public repository, the intended reporting path is private vulnerability reporting through the repository host. If private reporting is not yet enabled when the public remote is created, enable it before directing reporters to public issue tracking.

Until the final public remote is live, treat this file as the policy that public disclosure should wait for a private reporting channel.

What to Include

Please include:

  • affected component or package
  • impact and attack scenario
  • reproduction steps or proof of concept
  • version, branch, or commit information when available
  • any suggested mitigation or patch context

Scope

The most sensitive areas in ZWall Community include:

  • manager and agent authentication
  • token issuance, refresh, and persistence
  • registration and enrollment flows
  • certificate and TLS handling
  • eBPF/XDP and TC enforcement behavior
  • database migrations and initialization

Response Goals

Maintainers should acknowledge valid private reports quickly, assess impact, prepare a fix, and publish a coordinated disclosure once users have a safe upgrade path.

There aren't any published security advisories