| Version/Branch | Supported |
|---|---|
main |
Yes |
dev |
Best effort |
| Older branches/tags | No |
Please do not open public issues for security reports.
Use GitHub's private reporting flow:
- Open the repository Security tab.
- Click Report a vulnerability.
- Include reproduction steps, impact, affected version or tag, and deployment assumptions.
If private reporting is unavailable, contact a maintainer directly and share details privately.
- Initial triage response: within 7 days.
- Status update after validation: within 14 days.
- Fix timeline depends on severity, exploitability, and release risk.
This policy covers Traefik Proxy Admin application code, Docker images, release automation, and repository workflows.
TPA manages Traefik dynamic configuration, authentication hooks, target probes, and operational secrets. Treat deployment-specific findings involving exposed admin UI, exposed Traefik API, weak cookie domains, or broad target probe ranges as security-sensitive.