Security
Report vulnerabilities responsibly
TurboPanel is in public beta. We take security reports seriously and coordinate fixes before public disclosure.
Supported versions
| Channel | Security support |
|---|---|
| release (stable) | Security fixes |
| rc | Security fixes during RC window |
| canary | Best-effort — upgrade to release for production |
| trunk | Development only |
Pair control plane and daemon versions using the compatibility matrix.
Private reporting
- Use GitHub private vulnerability reporting on the affected repository.
- Or email security@turbopanel.io if private reporting is unavailable.
Full policy: Vulnerability reporting
Response timeline
- Acknowledgement
- 3 business days
- Initial assessment
- 10 business days
- Fix plan
- Severity-dependent; we keep you updated
Advisories
Published advisories appear on GitHub Security Advisories. Subscribe to release notifications for security fixes.