Skip to content

Security: RoFz/vault-plugin-secrets-keycloak

SECURITY.md

Security Policy

Supported Versions

Only the latest release is supported with security fixes.

Reporting a Vulnerability

Please do not open a public issue for security vulnerabilities.

Report vulnerabilities privately using GitHub Security Advisories. You will receive an acknowledgement within 7 days.

Scope

In scope:

  • Vulnerabilities in this plugin's code that could compromise the confidentiality, integrity, or availability of Vault or Keycloak credentials
  • Dependency vulnerabilities with a direct exploit path

Out of scope:

  • Vulnerabilities in HashiCorp Vault itself — report those to HashiCorp
  • Vulnerabilities in Keycloak itself — report those to the Keycloak project
  • Issues requiring physical access or social engineering

Disclosure

Once a fix is released, vulnerabilities will be publicly disclosed via a GitHub Security Advisory. Credit will be given to the reporter unless anonymity is requested.

References

This policy was shaped by the following sources:

There aren't any published security advisories