Please report security vulnerabilities privately through GitHub's private vulnerability reporting:
- Go to the repository's Security tab.
- Click Report a vulnerability.
- Fill in the advisory form.
Please do not open a public issue for security reports.
Every released artifact carries signed SLSA Build L2
provenance generated by GitHub Actions and signed with Sigstore. The container
image and the runtime image's SBOM are attached to the image in ghcr.io; the
release binaries, packages, and a source SBOM are attached to the GitHub Release.
Verify with the gh CLI (replace X.Y.Z with the
release version):
Container image:
gh attestation verify oci://ghcr.io/drzero42/nexorious:X.Y.Z --repo drzero42/nexorious
A downloaded release binary or package:
gh attestation verify ./nexorious_X.Y.Z_linux_amd64 --repo drzero42/nexorious
Helm chart:
gh attestation verify oci://ghcr.io/drzero42/charts/nexorious:X.Y.Z --repo drzero42/nexorious
Inspect the image SBOM:
gh attestation verify oci://ghcr.io/drzero42/nexorious:X.Y.Z --repo drzero42/nexorious --predicate-type https://spdx.dev/Document
The source SBOM (nexorious_X.Y.Z_sbom.source.spdx.json) is attached as a
release asset and is itself covered by the release provenance.