Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Appearance settings

Security: pshenok/stackcanvas

Security

SECURITY.md

Security Policy

Reporting a vulnerability

Please report security issues privately via GitHub Security Advisories for this repo — not a public issue or PR. We aim to respond within 72 hours.

Scope

  • The local canvas server (packages/server) and its /api/* routes, including the Host/Origin allowlist
  • Terraform/OpenTofu state and plan parsing (packages/core)
  • The telemetry pipeline: client (packages/server/src/telemetry.ts) and collector (telemetry-collector/)

Out of scope: vulnerabilities in Terraform/OpenTofu themselves, or in cloud provider APIs stackcanvas reads from.

There aren't any published security advisories

Morty Proxy This is a proxified and sanitized view of the page, visit original site.