[{"data":1,"prerenderedAt":148},["ShallowReactive",2],{"i-lucide:search":3,"i-lucide:sun":8,"i-lucide:menu":10,"security-en":12,"i-lucide:link":146},{"left":4,"top":4,"width":5,"height":5,"rotate":4,"vFlip":6,"hFlip":6,"body":7},0,24,false,"\u003Cg fill=\"none\" stroke=\"currentColor\" stroke-linecap=\"round\" stroke-linejoin=\"round\" stroke-width=\"2\">\u003Cpath d=\"m21 21l-4.34-4.34\"/>\u003Ccircle cx=\"11\" cy=\"11\" r=\"8\"/>\u003C/g>",{"left":4,"top":4,"width":5,"height":5,"rotate":4,"vFlip":6,"hFlip":6,"body":9},"\u003Cg fill=\"none\" stroke=\"currentColor\" stroke-linecap=\"round\" stroke-linejoin=\"round\" stroke-width=\"2\">\u003Ccircle cx=\"12\" cy=\"12\" r=\"4\"/>\u003Cpath d=\"M12 2v2m0 16v2M4.93 4.93l1.41 1.41m11.32 11.32l1.41 1.41M2 12h2m16 0h2M6.34 17.66l-1.41 1.41M19.07 4.93l-1.41 1.41\"/>\u003C/g>",{"left":4,"top":4,"width":5,"height":5,"rotate":4,"vFlip":6,"hFlip":6,"body":11},"\u003Cpath fill=\"none\" stroke=\"currentColor\" stroke-linecap=\"round\" stroke-linejoin=\"round\" stroke-width=\"2\" d=\"M4 5h16M4 12h16M4 19h16\"/>",{"doc":13,"isFallback":6},{"id":14,"title":15,"body":16,"description":137,"extension":138,"meta":139,"navigation":140,"path":141,"seo":142,"seoTitle":143,"stem":144,"__hash__":145},"securityEn/en/security.md","Security",{"type":17,"value":18,"toc":125},"minimark",[19,23,28,40,51,56,59,75,79,87,91,97,103,107,110,114,117],[20,21,22],"p",{},"Maran installs a daemon that runs as root and a panel that provisions system users. A defect here\nis not an inconvenience, so a report about one is welcome and will be answered.",[24,25,27],"h2",{"id":26},"reporting-a-vulnerability","Reporting a vulnerability",[20,29,30,31,39],{},"Write to ",[32,33,34],"strong",{},[35,36,38],"a",{"href":37},"mailto:security@innovayse.com","security@innovayse.com",". Do not open a public issue, and do not describe the problem in\na pull request before it is fixed. If you would rather encrypt, say so in a first message with no\ndetails and a key will be sent.",[20,41,42,43,46,47,50],{},"Reports are acknowledged within ",[32,44,45],{},"48 hours",". Critical issues target a fix or a documented\nmitigation within ",[32,48,49],{},"14 days","; less severe ones are scheduled and you are told when. Coordinated\ndisclosure is honoured, and you are credited by the name you choose unless you ask not to be.",[52,53,55],"h3",{"id":54},"what-to-include","What to include",[20,57,58],{},"Enough to reproduce it, and nothing that is not yours to send:",[60,61,62,66,69,72],"ul",{},[63,64,65],"li",{},"what an attacker gains — reading another tenant's files, escalating to root, bypassing a limit;",[63,67,68],{},"the smallest sequence that shows it, and which distribution and version you saw it on;",[63,70,71],{},"whether it needs an authenticated session, and at which role;",[63,73,74],{},"logs if they help, with tokens, hostnames and customer data removed.",[24,76,78],{"id":77},"test-against-your-own-installation","Test against your own installation",[20,80,81,82,86],{},"Probing somebody else's server running this software is not research, and no finding excuses it. A\nreport obtained that way is not accepted, and it may be a crime where you or they are. Installing\nyour own is ",[35,83,85],{"href":84},"/docs/installation","one command",".",[24,88,90],{"id":89},"scope","Scope",[20,92,93,96],{},[32,94,95],{},"In scope"," — everything the project ships: the panel API, the single-page application, the Rust\nagent and its socket, the installer, and the templates the agent renders. Reports about the design\nare in scope too: if a rule that was written down is the wrong rule, that is worth more than a bug.",[20,98,99,102],{},[32,100,101],{},"Out of scope"," — findings that require an attacker to already be root on the host, denial of\nservice by exhausting the machine's own resources, missing hardening headers with no demonstrated\nimpact, and reports produced only by a scanner with no reasoning attached.",[24,104,106],{"id":105},"supported-versions","Supported versions",[20,108,109],{},"Until 1.0, only the latest release receives fixes. After 1.0 the policy will name the versions that\ndo.",[24,111,113],{"id":112},"what-the-project-does-on-its-own-side","What the project does on its own side",[20,115,116],{},"Changes to authentication, sessions and tokens, to the agent's privilege handling, to licence\nverification, or to a privileged step in the installer require a second reviewer and a written\nthreat note before they merge. Dependencies are pinned and updated deliberately rather than by a\nbot, and secrets are never committed.",[20,118,119,120,124],{},"The architecture is the first line of this: the panel runs unprivileged, one small daemon holds\nroot, and the contract between them has no operation that runs a caller-supplied program. See\n",[35,121,123],{"href":122},"/docs","how it is built"," for what that means in practice.",{"title":126,"searchDepth":127,"depth":127,"links":128},"",2,[129,133,134,135,136],{"id":26,"depth":127,"text":27,"children":130},[131],{"id":54,"depth":132,"text":55},3,{"id":77,"depth":127,"text":78},{"id":89,"depth":127,"text":90},{"id":105,"depth":127,"text":106},{"id":112,"depth":127,"text":113},"How to report a vulnerability in Maran, what is in scope and what is not, the response times you can expect, and what the project does on its own side.","md",{},true,"/en/security",{"title":15,"description":137},"Report a vulnerability in Maran","en/security","_G8iVn1XXm6wglC7r4DqQf6w77GuSsJCU0e0_3XHgQs",{"left":4,"top":4,"width":5,"height":5,"rotate":4,"vFlip":6,"hFlip":6,"body":147},"\u003Cg fill=\"none\" stroke=\"currentColor\" stroke-linecap=\"round\" stroke-linejoin=\"round\" stroke-width=\"2\">\u003Cpath d=\"M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71\"/>\u003Cpath d=\"M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71\"/>\u003C/g>",1790166387883]