Skip to content

Security: burnableifx/nesos

SECURITY.md

Security policy

Nesos crosses Linux namespace and privilege boundaries, so security reports are taken seriously.

Reporting a vulnerability

Please do not open a public issue. Use GitHub's private vulnerability reporting to contact the maintainers privately.

Include the affected revision or version, Linux distribution and kernel version, reproduction steps, observed impact, and any suggested mitigation. Avoid including secrets or data belonging to other people.

Supported versions

Before 1.0, security fixes target the latest release and the main branch. Older pre-1.0 releases may require upgrading rather than receiving a backport.

Bridge transport boundary

The bridge broker always protects its control connection with TLS. That does not make raw VXLAN an authenticated or encrypted data plane. A VXLAN offer must explicitly classify its underlay as protected or unsafe; unsafe use also requires a client acknowledgement. Prefer the WireGuard transport across routed or untrusted locations, which carries VXLAN inside an authenticated encrypted tunnel. See the traffic and bridge guide for the policy and key-handling model.

There aren't any published security advisories