If you discover a security vulnerability in barrel_docdb, please report it responsibly.
DO NOT open a public issue for security vulnerabilities.
- Email: Send details to security@barrel-db.eu
- Include:
- Description of the vulnerability
- Steps to reproduce
- Potential impact
- Any suggested fixes (optional)
- Acknowledgment: Within 48 hours
- Initial Assessment: Within 5 business days
- Resolution Timeline: Depends on severity
- Critical: 7 days
- High: 14 days
- Medium: 30 days
- Low: 90 days
This policy applies to:
- barrel_docdb core library
- HTTP API endpoints
- Replication protocols
- Storage layer
- Issues in dependencies (report to upstream)
- Self-hosted deployment misconfigurations
- Social engineering attacks
| Version | Supported |
|---|---|
| 0.3.x | Yes |
| < 0.3 | No |
When deploying barrel_docdb:
- Network Security: Use TLS for HTTP endpoints
- Authentication: Enable authentication for production
- Access Control: Restrict database access appropriately
- Updates: Keep dependencies updated
- Monitoring: Enable metrics and alerting
We appreciate responsible disclosure and will acknowledge security researchers who report valid vulnerabilities (unless they prefer to remain anonymous).