Security fixes target the current main branch. Operators are responsible for assessing older deployments and local changes.
Please use GitHub's private vulnerability reporting form under the repository's Security tab. Do not open a public issue for a suspected vulnerability or include credentials, participant data, private host details, certificates, environment files, or deployment receipts in a report.
Include the affected commit, the rendered service boundary without secrets, reproduction steps using generated data, and the expected impact. Maintainers will acknowledge the report, validate it, and coordinate a fix and disclosure when appropriate.
Marine is a deployment template, not a managed service. Operators must supply reviewed immutable image references, unique credentials, private storage paths, TLS material, backups, monitoring, and rollback capacity. Validate the fully rendered Compose configuration before it reaches a host with real data.