Security
Security Policy
Section titled “Security Policy”Supported Versions
Section titled “Supported Versions”Ceres is currently in early development (pre-v1.0). Security updates will be provided for the latest development version.
| Version | Supported |
|---|---|
| main | :white_check_mark: |
Reporting a Vulnerability
Section titled “Reporting a Vulnerability”If you discover a security vulnerability in Ceres, please report it privately:
- Do not open a public issue
- Email the maintainers or use GitHub’s private vulnerability reporting
- Include:
- Description of the vulnerability
- Steps to reproduce
- Potential impact
- Suggested fix (if any)
We will respond within 48 hours and work with you to address the issue.
Security Considerations
Section titled “Security Considerations”When using Ceres:
- API Keys: Never commit API keys or database credentials to version control
- Admin Endpoints: Protect harvest and admin API endpoints with a strong
CERES_ADMIN_TOKEN(Bearer token auth) - Public Metadata:
GET /api/v1/datasets/{id}recursively strips keys configured byCERES_METADATA_REDACT_KEYS; stored metadata and authenticated exports remain unchanged - CORS: Keep
CORS_ALLOWED_ORIGINS=*for local development only; production deployments should list explicit trusted origins - Database: Use strong passwords for PostgreSQL and restrict network access
- Input Validation: Be cautious when harvesting from untrusted data portals
- Dependencies: Keep Rust dependencies updated with
cargo update; runcargo deny checkfor audits
Disclosure Policy
Section titled “Disclosure Policy”Once a security issue is fixed, we will:
- Release a patch
- Publish a security advisory
- Credit the reporter (unless they prefer anonymity)