Security

Report vulnerabilities responsibly

TurboPanel is in public beta. We take security reports seriously and coordinate fixes before public disclosure.

Supported versions

ChannelSecurity support
release (stable)Security fixes
rcSecurity fixes during RC window
canaryBest-effort — upgrade to release for production
trunkDevelopment only

Pair control plane and daemon versions using the compatibility matrix.

Private reporting

  1. Use GitHub private vulnerability reporting on the affected repository.
  2. Or email security@turbopanel.io if private reporting is unavailable.

Full policy: Vulnerability reporting

Response timeline

Acknowledgement
3 business days
Initial assessment
10 business days
Fix plan
Severity-dependent; we keep you updated

Advisories

Published advisories appear on GitHub Security Advisories. Subscribe to release notifications for security fixes.