Ssabba is early software. Only the latest release on main receives security fixes.
Report privately through GitHub security advisories. Please do not open a public issue for a vulnerability.
Include what you can: affected version or commit, how the instance is deployed, reproduction steps, and the impact you believe it has. You will get an acknowledgement within a few days, and an advisory with credit once a fix is available.
- Never weaken
Oidc:RequireHttpsMetadataoutside development. - Every
change-mevalue indeploy/.env.exampleis a secret and must be replaced before exposing an instance to the internet. deploy/.env, ACME storage and anything underdeploy/**/data/must stay out of version control.- Issue the CrowdSec bouncer key after the first start; without it Traefik's bouncer is inert.