Files
Kevin AdamsandClaude Sonnet 4.6 636cd06ff6 Phase 1 project revival + PR fixes (#207, #209, #213)
Project infrastructure:
- Replace MIT license with AGPL-3.0 (KSA Technologies, LLC)
- Full README rewrite with badges, compatibility table, token auth docs
- Add CHANGELOG, CONTRIBUTING, DONORS, SECURITY docs
- Add GitHub issue/PR templates, update FUNDING.yml and stale.yml
- Replace external packer repo dispatch with self-contained CI (build.yml)
- Add packaging/DEBIAN/ with postinst/postrm/triggers (no git clone at install)
- Add .perlcriticrc for static analysis
- Add .claude/cos/ ADRs, plans, and runbooks

Bug fixes from community PRs:
- Fix bearer token check in freenas_api_connect: defined() && value instead of
  defined() alone, so truenas_token_auth=0 no longer activates Bearer Token auth (#207)
- Fix LUN 0 falsy bug in ZFSPlugin patch: !$guid -> !defined $guid in both
  zfs_get_lun_number and zfs_get_wwid_number, fixing VMs on LUN 0 for PVE 9 (#209)
- Fix syslog typo "wtih" -> "with" in run_list_extent (#213)

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-05-15 14:22:04 -04:00

1.4 KiB

Security Policy

Supported Versions

Version Supported
3.x (upcoming) Yes
2.3.x Yes
2.2.x and earlier No — please upgrade

Reporting a Vulnerability

Do not open a public GitHub issue for security vulnerabilities.

Email security reports to: security@ksatechnologies.com (or theprofessor@ksatechnologies.com)

Include:

  • A description of the vulnerability
  • Steps to reproduce
  • The potential impact
  • Any suggested fixes if you have them

You will receive an acknowledgment within 72 hours. We aim to release a fix within 14 days for confirmed vulnerabilities and will credit reporters in the release notes unless anonymity is requested.

Security Considerations for Operators

  • API tokens are stored in /etc/pve/storage.cfg which is readable only by root and replicated across the PVE cluster via pmxcfs. Treat cluster access accordingly.
  • Use API token authentication rather than username/password. Tokens can be revoked individually without changing your TrueNAS user password.
  • Enable SSL on the TrueNAS API connection. The plugin accepts self-signed certificates (SSL verification is relaxed) — use a private CA or valid certificate where possible.
  • Scope API tokens to the minimum required permissions on TrueNAS if your version supports scoped tokens.
  • Restrict network access to the TrueNAS management interface to only the Proxmox nodes that need it.