Skip to content

Security: drzero42/nexorious

SECURITY.md

Security Policy

Reporting a vulnerability

Please report security vulnerabilities privately through GitHub's private vulnerability reporting:

  1. Go to the repository's Security tab.
  2. Click Report a vulnerability.
  3. Fill in the advisory form.

Please do not open a public issue for security reports.

Verifying releases

Every released artifact carries signed SLSA Build L2 provenance generated by GitHub Actions and signed with Sigstore. The container image and the runtime image's SBOM are attached to the image in ghcr.io; the release binaries, packages, and a source SBOM are attached to the GitHub Release. Verify with the gh CLI (replace X.Y.Z with the release version):

Container image:

gh attestation verify oci://ghcr.io/drzero42/nexorious:X.Y.Z --repo drzero42/nexorious

A downloaded release binary or package:

gh attestation verify ./nexorious_X.Y.Z_linux_amd64 --repo drzero42/nexorious

Helm chart:

gh attestation verify oci://ghcr.io/drzero42/charts/nexorious:X.Y.Z --repo drzero42/nexorious

Inspect the image SBOM:

gh attestation verify oci://ghcr.io/drzero42/nexorious:X.Y.Z --repo drzero42/nexorious --predicate-type https://spdx.dev/Document

The source SBOM (nexorious_X.Y.Z_sbom.source.spdx.json) is attached as a release asset and is itself covered by the release provenance.

There aren't any published security advisories