Skip to content

Security: 0xAstroAlpha/cliProxyAPI-Dashboard

Security

SECURITY.md

Security Policy

πŸ”’ Supported Versions

Version Supported
6.x βœ… Yes
5.x ⚠️ Security fixes only
< 5.0 ❌ No

🚨 Reporting a Vulnerability

We take security seriously. If you discover a security vulnerability, please follow these steps:

Do NOT:

  • ❌ Open a public GitHub issue
  • ❌ Post about it on social media
  • ❌ Share details publicly before it's fixed

Do:

  1. Email us directly at: security@astroalpha.dev (or contact via Facebook)
  2. Include:
    • Description of the vulnerability
    • Steps to reproduce
    • Potential impact
    • Any suggested fixes (optional)

What to Expect:

  • πŸ“¬ Acknowledgment within 48 hours
  • πŸ” Initial assessment within 1 week
  • πŸ› οΈ Fix timeline communicated based on severity
  • πŸ† Credit given in release notes (if desired)

πŸ›‘οΈ Security Best Practices

When deploying CLIProxy Dashboard:

  1. Always use a strong secret-key in your config.yaml
  2. Never expose port 8317 directly to the internet without authentication
  3. Use HTTPS in production (via reverse proxy like Nginx/Caddy)
  4. Regularly update to the latest version
  5. Limit access to the management dashboard to trusted IPs

πŸ“œ Disclosure Policy

We follow a 90-day disclosure policy:

  • After a vulnerability is reported, we have 90 days to release a fix
  • After the fix is released, we will publish a security advisory

Thank you for helping keep CLIProxy Dashboard secure! πŸ™

There aren’t any published security advisories