SFTPWarden is infrastructure software. Please treat vulnerabilities, accidental secret exposure, and unsafe deployment patterns seriously.
The current stable release line is supported for security fixes. Older minor versions may receive fixes only at the maintainer's discretion when the impact is high and a backport is practical.
Do not open a public issue for vulnerabilities.
Use GitHub private vulnerability reporting or the security advisory flow when available. Otherwise, contact the project owner privately.
Please include:
- affected version or commit;
- affected component: CLI, runtime, watcher, provider, Docker image, docs, or CI;
- steps to reproduce;
- expected impact;
- logs or screenshots with secrets redacted;
- whether the issue is already public or exploited.
Examples:
- plaintext secrets written to disk or logs;
- private keys or DSNs included in examples, tests, images, or docs;
- remote command injection;
- unsafe SSH, rsync, or scp command construction;
- Docker watcher mounting broad host credentials;
- broken chroot permissions;
- provider mutations that bypass validation;
- authentication or disabled-user behavior that grants unintended access.
SFTPWarden provides OpenSSH chroot isolation inside a container. It does not replace:
- host hardening;
- network firewalling;
- patch management;
- backups;
- log monitoring;
- secret management;
- an independent review before internet-facing production use.
Do not expose experimental deployments to the public internet without a review of the host, firewall, Docker configuration, SSH settings, and provider data.