We actively maintain and issue security patches for the following versions of OpenBack:
| Version | Supported |
|---|---|
| 0.2.x | ✅ |
| 0.1.x | ❌ |
We take the security of OpenBack (openbackd runtime engine and backcli orchestrator) very seriously. If you discover a security vulnerability, please do NOT open a public GitHub issue.
- Private Vulnerability Reporting: Use the GitHub Private Vulnerability Reporting feature on this repository.
- Email: Alternatively, email us directly at
reyhank45@fedoraor your designated security contact.
Please include as much detail as possible to help us reproduce and fix the issue:
- Type of issue (e.g., namespace breakout, privilege escalation, unauthorized RPC access, token bypass).
- A minimal Proof of Concept (PoC) script or
backclimanifest demonstrating the flaw. - Affected components (
openbackd,backcli,openback-control). - Step-by-step instructions to reproduce.
- Initial Response: Within 48 hours of receiving the report.
- Status Update: Within 7 days with an estimated fix release date.
- Public Disclosure: Coordinated after a patch is merged and released to protect production users.
Thank you for helping keep OpenBack and the open-source container ecosystem secure!