DEYROUTE runs as root on servers that carry other people's traffic, so security reports are welcome and handled first.
Please report privately through
GitHub security advisories,
not in a public issue. Include the version (deyroute version), what an
attacker can do, and how to reproduce it. You will get an answer within a few
days.
- the control channel between hub and nodes (mutual TLS, join tokens)
- the release chain:
SHA256SUMSsigned with minisign, checked by the installer anddeyroute updatebefore anything is installed - secrets on disk (tunnel tokens, CA key: mode 0600) and in logs (redacted)
- the firewall rules DEYROUTE writes (its own nftables tables only)
How these work is described in docs/en/security.md (فارسی).
Only the newest release receives fixes. The hub updates itself once a day
(deyroute update auto), and nodes follow the hub.
لطفاً مشکلهای امنیتی را بهصورت خصوصی از طریق
GitHub security advisories
گزارش دهید، نه در Issue عمومی. نسخه (deyroute version)، کاری که مهاجم میتواند بکند و
روش بازتولید را بنویسید. فقط جدیدترین نسخه اصلاح میشود؛ هاب روزی یک بار خودش آپدیت میشود.