Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Appearance settings

Latest commit

 

History

History
History
21 lines (11 loc) · 1.67 KB

File metadata and controls

21 lines (11 loc) · 1.67 KB
Copy raw file
Download raw file
Outline
Edit and raw actions

Security

Use this file for vulnerability reports. For the security model, production guidance, audit, and already-answered public findings, start with Security Documentation.

Report a vulnerability

If you believe you found a vulnerability, please use GitHub's private security reporting features for this repository. If GitHub private reporting is unavailable, contact security@phala.network.

Do not open public GitHub issues for exploitable vulnerabilities or details that could help exploit production deployments.

Use private reporting for issues that could expose secrets, bypass attestation or authorization, compromise KMS keys, weaken workload isolation, or enable unauthorized code or configuration changes in production deployments.

Public security questions

Use public issues only for questions about documented behavior, documentation gaps, already-public findings, or hardening ideas that do not include an exploit path.

Before opening a public security question, check Public Security Reports. It records public report status and related hardening or roadmap work.

Production trust boundary

Development settings are not production-safe merely because they are present in the codebase. Production deployments must rely on measured configuration, expected TEE measurements, authorization policy, and attestation verification. The Security Model is the source of truth for what dstack treats as a production guarantee.

Morty Proxy This is a proxified and sanitized view of the page, visit original site.