cache-database publishes stable releases. Security support covers:
- the latest published stable minor line
- the latest
mainbranch while a fix is being prepared for release
Older snapshots may not receive fixes.
Please do not file public GitHub issues for security problems.
Use GitHub private vulnerability reporting for this repository when it is enabled. If that path is unavailable, contact the maintainers through the private security contact configured for the repository administrators.
When reporting, include:
- affected module(s)
- impacted version or commit
- reproduction details
- whether the issue affects correctness, confidentiality, integrity, or availability
- any mitigation you already tested
We will acknowledge the report, assess severity, and work toward a fix and coordinated disclosure plan.
This project relies on Redis and the selected durable SQL provider for correctness and durability behavior. Production deployments should treat:
- Redis durability and failover posture
- credential management
- network policy
- access control
- private admin surfaces
as part of the security boundary, not just performance tuning.
The Spring Boot admin HTTP surface is not published unless
cachedb.admin.http-enabled=true is configured explicitly.
Production deployments must keep /cachedb-admin/** behind a gateway,
operations network, or equivalent access-control boundary. Application-level
TLS is not mandatory when TLS terminates at the gateway or reverse proxy, but
direct public exposure is not an accepted production posture.
If gateway authentication is not used, enable CacheDB token auth:
cachedb:
admin:
http-enabled: true
auth-enabled: true
auth-token: ${CACHEDB_ADMIN_TOKEN}