| Version | Supported |
|---|---|
| 0.1.x | Yes |
If you discover a security vulnerability in Confluence, please report it responsibly.
Do not open a public GitHub issue for security vulnerabilities.
-
Email or DM with details of the vulnerability
-
Include:
- Description of the issue
- Steps to reproduce
- Potential impact
- Suggested fix (if any)
-
Allow reasonable time for a fix before public disclosure
- Acknowledge receipt within 48 hours
- Provide an estimated timeline for a fix
- Credit you in the changelog (unless you prefer anonymity)
- No authentication — the API is designed for local development and trusted deployments. For production, place behind an authenticated reverse proxy.
- Rate limiting — not yet implemented. Deploy behind a rate-limiting proxy in production.
- Input validation — Pydantic schemas enforce bounds on all request fields.
- CORS — configurable via
CORS_ORIGINSenv var. Never set to*in production. - WebSocket DoS protection — all user-controlled parameters (resolution, n_estimators, max_depth, n_epochs, max_epochs) are clamped to safe maximums.
- Redis has no authentication by default in Docker Compose
- No HTTPS termination — use a reverse proxy (Nginx, Caddy) for TLS
- No request logging or audit trail
- No brute-force protection
- Never expose Redis to the public internet without authentication
- Use HTTPS via a reverse proxy (Nginx, Caddy, Cloudflare)
- Set
CORS_ORIGINSto your exact frontend domain — never* - Use a non-root user in Docker (add
USER appuserto Dockerfiles) - Add rate limiting via Nginx
limit_reqor a dedicated proxy - Monitor logs for unusual request patterns
- Keep dependencies updated — run
pip auditandnpm auditregularly
# Backend
cd backend && pip-audit
# Frontend
cd frontend && npm auditNone reported yet.