Only the latest minor release receives security updates. Pin to the most recent tag for production use.
Email security@jordannewell.com with:
- A description of the issue and its impact
- Reproduction steps (a minimal example is ideal)
- Affected version — run
harbormasterd --version
Do not open a public GitHub issue for security reports.
If you have a PGP key, encrypt your report. GPG fingerprint of the project's reporting key:
67567DC5E7C5353F85F2AF0DAC05D3F3E0EFA32A
- Acknowledgment: within 72 hours
- Initial assessment: within 5 business days
- Fix or mitigation: target 30 days for high-severity issues
Please refrain from public disclosure until a fix has been published, to protect downstream users. Reporters will be credited in the release notes unless they prefer otherwise.
In scope:
- The daemon (
harbormasterdand its subcommands) - Certificate management (mkcert integration)
- DNS handling
harbormasterd manages local TLS certificates, so any report about certificate handling, key storage, or privilege escalation is treated as high-priority.
Out of scope:
- mkcert itself — report upstream
- The local DNS server implementation
- OS-level networking