This project is pre-1.0 and receives best-effort security updates on main.
Please do not open public issues for vulnerabilities.
Report privately via repository security advisory or maintainer contact. Include:
- Affected version/commit
- Reproduction details
- Impact assessment
We will acknowledge within 72 hours and work on a fix.
- Treat Docker API access as privileged.
- Prefer
docker-socket-proxywith allowlisted endpoints. - Keep destructive actions gated by explicit approvals.
- Rotate API keys and never commit
.env.