| Version | Supported |
|---|---|
| 1.x | ✅ |
We take security seriously. If you discover a security vulnerability, please report it responsibly.
Do NOT create a public GitHub issue.
Instead, please either:
-
GitHub Security Advisories (Preferred)
- Go to Security Advisories
- Click "Report a vulnerability"
- Fill in the details
-
Email
- Send details to: security@dockrouter.dev
- Include: description, steps to reproduce, potential impact
- Description of the vulnerability
- Steps to reproduce
- Affected versions (if known)
- Potential impact
- Any suggested fixes (optional)
- Initial Response: Within 48 hours
- Triage: Within 7 days
- Fix Development: Depends on severity
- Disclosure: After fix is released
- We follow responsible disclosure
- We ask that you give us reasonable time to fix the issue before public disclosure
- We will credit you in the security advisory (unless you prefer to remain anonymous)
DockRouter is designed with security in mind:
- Zero dependencies - No supply chain attack surface
- Minimal attack surface - Single binary, no plugins
- Constant-time auth - bcrypt comparison resistant to timing attacks
- Scratch-based Docker image - Minimal container footprint
- No external network calls - Except for ACME (Let's Encrypt)
When deploying DockRouter:
- Protect the Docker socket - Mount as read-only (
:ro) - Secure the admin port - Bind to localhost or use firewall rules
- Use strong auth credentials - Generate bcrypt hashes with high cost
- Keep updated - Use the latest release version
- Review labels - Only expose containers that need to be public
# Example: Secure admin port binding
docker run -p 9090:9090 \
-e DR_ADMIN_ADDR=127.0.0.1:9090 \
...Thank you for helping keep DockRouter secure!