Files
inbuxa-server/SECURITY.md
T
jcoffey-dev 72f8ddd5e7 Import upstream v0.16.25, stripped
Upstream commit: 3f657330c0f49a015a3a372fb59669b5cccbca6d
Enterprise-only files removed or emptied: 63
Enterprise-only snippets removed: 118 in 50 files
Dangling module declarations removed: 5
Edits turning enterprise off: 25
Third-party code: 14 files, 0 not in THIRD-PARTY.md
Renamed identifiers: 67 in 19 files
Verification: clean

The same Enterprise footprint as v0.16.24. The build check is clean
apart from the expected errors in the rebuilt-feature tests. A
bug-fix release: DKIM rotation, IMAP failed-login answers, DNSBL
multi-code scoring and negative TTLs, Pyzor on short messages, queue
quotas with an empty match, RocksDB info-log rotation, and
Autodiscover schema handling.
2026-10-05 21:15:02 -07:00

1.4 KiB

Security policy

Supported versions

INBUXA is developed on main, and security fixes are applied there and in the latest release. Older tags are not backported.

Version Supported
main and the latest release ✅
Older releases ❌

Reporting a vulnerability

Please don't open a public issue for a security problem. An issue is visible to everyone, including whoever would use it, before there is a fix.

Report it privately by email to:

johnellisATlinuxDOTcom

Include as much as you can of:

  • what the vulnerability is, and what it lets someone do;
  • how to reproduce it, or a proof of concept;
  • the version or commit affected;
  • anything about the deployment that matters — backend, front ends, whether it needs an authenticated account.

You'll get an acknowledgement within a few days. If a report turns out to affect upstream Stalwart rather than this fork's own code, it will be passed to Stalwart Labs with credit to you, and you'll be told that has happened.

Scope

This repository is the mail server. The web front ends have their own:

Upstream's own security documents are kept in .github-upstream/ for reference. They describe Stalwart Labs' process, not this project's.