Report a vulnerability
Use GitHub private vulnerability reporting, as described in SECURITY.md. Do not open a public issue, discussion or pull request for a vulnerability.
SECURITY.md also sets out what to expect: an acknowledgement within 7 days, an initial assessment within 14 days, and which reports are in scope.
What CloudBurrow is not
CloudBurrow is a local emulator for development and testing. These are documented properties, not bugs:
- The emulated APIs have no authentication. docs/configuration.md
- Secret Manager is not a secret store. SECURITY.md
- Cloud KMS is not a security boundary; key material is stored unencrypted. SECURITY.md
- IAM policies are stored, never enforced. SECURITY.md
- It binds loopback by default;
--allow-remotechanges that. docs/configuration.md
Supply chain
Each release archive has a SHA-256 checksum and a GitHub build attestation; the install script refuses an archive it cannot verify. docs/install.md