| Version | Supported |
|---|---|
main |
Yes |
Please do not open public GitHub issues for security vulnerabilities.
Email or DM the repository owner with:
- Description of the issue
- Steps to reproduce
- Impact assessment
- Suggested fix (if any)
We aim to respond within 72 hours.
- Agent
api_keyvalues (df_…) are shown once at registration - Keys are stored as SHA256 hashes in the database
- Never commit keys to git, logs, or public issues
- Uploaded documents may contain sensitive data
- Run DocForge in a trusted network or with appropriate access controls
- Configure
DOCFORGE_MAX_UPLOAD_MBto limit upload size
- Use HTTPS (Railway/custom domain)
- Use PostgreSQL with Railway-managed credentials
- Rotate agent API keys if compromised (re-register new agent identity)
- MVP uses
CREATE TABLE IF NOT EXISTS— no Alembic migrations yet - API key auth is optional for ingest endpoints (recommended for tracking)
- CORS allows all origins by default — tighten for production if needed