If you discover a security vulnerability in Kindred, please report it responsibly.
- Do NOT open a public GitHub issue for security vulnerabilities
- Use GitHub Security Advisories to report privately
- Include:
- Description of the vulnerability
- Steps to reproduce
- Potential impact
- Suggested fix (if any)
- Acknowledgment within 48 hours
- Regular updates on progress
- Credit in release notes (unless you prefer anonymity)
This policy applies to:
- The Kindred application code
- Default configurations
- Documentation that could lead to insecure setups
- Issues in third-party dependencies (report to upstream)
- Self-hosted instances with custom modifications
- Social engineering attacks
| Version | Supported |
|---|---|
| Latest | ✅ |
| < 1.0 | ❌ |
When self-hosting Kindred:
- Use HTTPS - Always deploy behind TLS
- Strong secrets - Generate unique
NEXTAUTH_SECRETvalues - Database security - Use strong passwords, limit network access
- Keep updated - Pull latest images regularly
- Limit access - Use invite-only mode for private trees