Skip to content
Development docs, for main @ c56b482 - what's coming, not yet released. This page for v2026.10.05-5, the latest release →

Security policy

Janus is alpha software: only the latest release gets security fixes. A node moves to it with its own A/B update (from the Controller, or janusctl lifecycle upgrade), signature checked and rolled back if it doesn’t come up healthy.

Please report it privately, through GitHub: Security tab → Report a vulnerability (new report) - never in a public issue. Say what is affected (a node’s API, HAProxy’s configuration handling, the Controller, an image…), the release, and how to reproduce it.

You get an answer within 3 days. The fix ships in a release:

SeverityTarget
Critical72 hours
High7 days
Medium, lowthe next release

A vulnerability in a component Janus ships but doesn’t develop (the kernel, HAProxy, an extension’s daemon…) is fixed by updating it as soon as upstream has a fix; please report it upstream too.

Every upstream component is pinned: versions and checksums in versions.mk, each download checked against its sha256 - pinned after checking upstream’s signature where upstream signs its releases. Go modules, the Controller’s npm packages, base images and CI actions are kept up to date by Dependabot.

A release that fixes vulnerabilities:

  • is named “Janus vX (Alpha) - 🔒 security update”, and says what it fixes in a 🔒 section of its notes;
  • carries security.json (what it fixes, machine-readable) and sbom.cdx.json (what it is made of, CycloneDX);
  • shows up in the Controller: nodes running an older release get a 🔒 security update badge, rated by the worst vulnerability they miss, and so does the Controller itself;
  • gets a GitHub security advisory (Security tab) for each vulnerability of Janus’s own code it fixes, whatever its severity, and one for the components it updates when what they fix is rated high or critical.

To be notified, watch the repository: Watch → Custom → Releases (or follow the releases’ Atom feed). GitHub’s “Security alerts” watch option only ever reaches the repository’s maintainers, and GitHub notifies nobody of a published advisory.

How upstream releases are followed, checked and assessed: Following upstreams.