Skip to content

Security: Anubhav1451/GovSwarm

Security

SECURITY.md

Security Policy

Supported Versions

The following versions of GovSwarm V2 currently receive security updates:

Version Supported
2.8.x ✅
< 2.8.0 ❌

Reporting a Vulnerability

If you discover a security vulnerability in GovSwarm V2, we appreciate your help in disclosing it to us in a responsible manner.

Please Do Not

  • Publicly disclose the vulnerability before a fix is available
  • Use the vulnerability to exploit or attack any system
  • Submit high-volume automated vulnerability reports

Reporting Process

  1. Email: Send a detailed report to govswarm-security@example.com (replace with actual security contact).
  2. GPG Key: You may encrypt your report using our GPG key (available upon request).
  3. Response Time: We aim to acknowledge receipt within 48 hours and provide a timeline for a fix within 7 days.
  4. Bounty: We do not currently offer a bug bounty program, but we will publicly acknowledge responsible disclosures.

Security Best Practices for Users

  • Always use the latest supported version
  • Set strong, unique JWT secrets (JWT_ACCESS_SECRET and JWT_REFRESH_SECRET, minimum 32 characters)
  • Configure HTTPS/TLS in production (reverse proxy strongly recommended)
  • Review and restrict ALLOWED_ORIGINS to your actual frontend domains
  • Keep your PostgreSQL credentials secure and rotate them regularly
  • Run npm audit periodically and address high-severity vulnerabilities

Known Security Considerations

  • The in-memory rate limiter and cache do not scale horizontally. Use Redis for multi-instance deployments.
  • 2 high-severity transitive dependency vulnerabilities exist (not directly exploitable in current usage). Run npm audit fix with caution.
  • No HTTPS/TLS is configured out-of-the-box. A reverse proxy (Caddy/nginx) is required for production.

Security Features

  • JWT-based authentication with access and refresh tokens
  • bcrypt password hashing (12 rounds)
  • Role-based access control (RBAC: ADMIN, OPERATOR, VIEWER)
  • Helmet.js security headers
  • CORS with configurable origin restriction
  • Sliding-window rate limiting
  • Input validation via Zod schemas
  • Graceful shutdown with resource cleanup

Acknowledgments

We thank all security researchers who have responsibly disclosed vulnerabilities to help keep GovSwarm V2 secure.

There aren't any published security advisories