The following versions of GovSwarm V2 currently receive security updates:
| Version | Supported |
|---|---|
| 2.8.x | ✅ |
| < 2.8.0 | ❌ |
If you discover a security vulnerability in GovSwarm V2, we appreciate your help in disclosing it to us in a responsible manner.
- Publicly disclose the vulnerability before a fix is available
- Use the vulnerability to exploit or attack any system
- Submit high-volume automated vulnerability reports
- Email: Send a detailed report to
govswarm-security@example.com(replace with actual security contact). - GPG Key: You may encrypt your report using our GPG key (available upon request).
- Response Time: We aim to acknowledge receipt within 48 hours and provide a timeline for a fix within 7 days.
- Bounty: We do not currently offer a bug bounty program, but we will publicly acknowledge responsible disclosures.
- Always use the latest supported version
- Set strong, unique JWT secrets (
JWT_ACCESS_SECRETandJWT_REFRESH_SECRET, minimum 32 characters) - Configure HTTPS/TLS in production (reverse proxy strongly recommended)
- Review and restrict
ALLOWED_ORIGINSto your actual frontend domains - Keep your PostgreSQL credentials secure and rotate them regularly
- Run
npm auditperiodically and address high-severity vulnerabilities
- The in-memory rate limiter and cache do not scale horizontally. Use Redis for multi-instance deployments.
- 2 high-severity transitive dependency vulnerabilities exist (not directly exploitable in current usage). Run
npm audit fixwith caution. - No HTTPS/TLS is configured out-of-the-box. A reverse proxy (Caddy/nginx) is required for production.
- JWT-based authentication with access and refresh tokens
- bcrypt password hashing (12 rounds)
- Role-based access control (RBAC: ADMIN, OPERATOR, VIEWER)
- Helmet.js security headers
- CORS with configurable origin restriction
- Sliding-window rate limiting
- Input validation via Zod schemas
- Graceful shutdown with resource cleanup
We thank all security researchers who have responsibly disclosed vulnerabilities to help keep GovSwarm V2 secure.