We release patches for security vulnerabilities. The project ships date-versioned nightly releases; the latest nightly is the supported line:
| Version | Supported |
|---|---|
latest nightly (2026.x) |
✅ |
0.x (legacy SemVer) |
❌ |
We take the security of Bamboo seriously. If you have discovered a security vulnerability, please report it to us.
Please do not report security vulnerabilities through public GitHub issues.
Instead, please report them via email to: mugeng.du@gmail.com
You should receive a response within 48 hours. If for some reason you do not, please follow up via email to ensure we received your original message.
Please include the following information in your report:
- Type of issue (e.g., buffer overflow, SQL injection, cross-site scripting, etc.)
- Full paths of source file(s) related to the manifestation of the issue
- The location of the affected source code (tag/branch/commit or direct URL)
- Any special configuration required to reproduce the issue
- Step-by-step instructions to reproduce the issue
- Proof-of-concept or exploit code (if possible)
- Impact of the issue, including how an attacker might exploit it
- Acknowledgment: We'll acknowledge receipt of your report within 48 hours
- Assessment: We'll assess the vulnerability and determine its severity
- Fix: We'll work on a fix and prepare a security release
- Disclosure: We'll coordinate disclosure with you
- We will not disclose the vulnerability until a fix is ready
- We will credit you in the security advisory (unless you prefer to remain anonymous)
- We request that you do not disclose the vulnerability publicly until we have released a fix
When using Bamboo in production:
- Keep updated: Always use the latest stable version
- Secure your API keys: Never commit API keys to version control
- Use environment variables: Store sensitive configuration in environment variables
- Enable rate limiting: Use the built-in rate limiting features
- Configure CORS: Properly configure CORS for your use case
- Regular audits: Regularly audit your dependencies with
cargo audit
Bamboo includes several built-in security features:
- ✅ Rate Limiting: Built-in protection against DoS attacks
- ✅ CORS Configuration: Configurable Cross-Origin Resource Sharing
- ✅ Input Validation: Comprehensive input validation and sanitization
- ✅ Secure Headers: Security headers for HTTP responses
- ✅ Encrypted Storage: Encrypted storage for sensitive data
- ✅ API Key Protection: Secure handling of LLM provider API keys
- API keys for LLM providers are stored in configuration files
- We recommend using environment variables for production deployments
- Never commit API keys to version control
- By default, Bamboo binds to
127.0.0.1(localhost only) - For production, configure appropriate firewall rules
- Use HTTPS in production environments
We regularly audit our dependencies for known vulnerabilities:
# Run security audit
cargo auditSecurity updates will be released as patch versions and announced via:
- GitHub Security Advisories
- Release notes on GitHub
- crates.io updates
For any security-related questions or concerns, contact:
Last Updated: 2026-02-23