Skip to content

Security: laranail/installer-web

SECURITY.md

Security

Where this file is silent, the laranail security policy applies.

Supported versions

Version Status
0.x Active support

Reporting a vulnerability

Please do not open a public GitHub issue for security-sensitive findings. Email security@simtabi.com with a description, reproduction steps, and the affected version(s). We aim to acknowledge within 72 hours.

Prefer GitHub private vulnerability reporting when you can: open it from this repository's Security tab. The report arrives attached to the repo with a draft advisory and a CVE request path already in place. Email is the fallback for anyone who would rather not use GitHub.

Hardening notes

  • Wizard routes are protected by the install-once guard, CSRF (the web group) and rate limiting.
  • The web layer never writes the .env or the database directly — all work is delegated to the headless engine, which writes the .env atomically and masks secrets in logs.

There aren't any published security advisories