🇬🇧 English | 🇩🇪 Deutsch
Security fixes are provided for the current release line only.
| Version | Supported |
|---|---|
| 1.8x (current release line) | ✅ |
| everything older | ❌ |
Always run the latest image (ghcr.io/s3lfcod3r/selfstream:latest) to receive security updates.
Please report security issues privately — do not open a public GitHub issue for a vulnerability.
- Email: info@selfcoder.de
- Include: affected version, a description of the issue, and steps to reproduce (a proof of concept helps).
- You will receive an acknowledgement as soon as possible. We aim to confirm the report and discuss a fix or mitigation timeline with you.
Please give us a reasonable window to ship a fix before any public disclosure (coordinated/responsible disclosure).
selfstream is intended to run on a trusted home/lab network. The admin panel (port 8080) should not be exposed directly to the internet. Issues that require an already-compromised LAN or direct internet exposure of the admin panel are considered out of the normal threat model, but we still welcome reports.
- The container runs as
rootand needsCAP_NET_ADMINplus/dev/net/tunto bring up the WireGuard/OpenVPN tunnel. The root filesystem is not read-only. Dropping privileges is not a one-line change (the tunnel setup needs them) and requires VPN testing, so it is tracked as an open item rather than shipped untested. - During setup over plain HTTP in the LAN the new admin token travels unencrypted. That is accepted within the threat model above, but you should be aware of it — set the token on a network you trust.
Sicherheits-Updates gibt es nur für die aktuelle Release-Linie.
| Version | Unterstützt |
|---|---|
| 1.8x (aktuelle Release-Linie) | ✅ |
| alles Ältere | ❌ |
Bitte immer das aktuelle Image (ghcr.io/s3lfcod3r/selfstream:latest) verwenden.
- Der Container läuft als
rootund brauchtCAP_NET_ADMINsowie/dev/net/tunfür den WireGuard-/OpenVPN-Tunnel. Das Root-Dateisystem ist nicht schreibgeschützt. Die Rechte abzulegen ist kein Einzeiler (der Tunnelaufbau braucht sie) und muss mit echten VPN-Tests abgesichert werden — deshalb steht es hier als offener Punkt statt ungetestet im Release. - Bei der Einrichtung über reines HTTP im LAN geht das neue Admin-Token im Klartext über das Netz. Im oben beschriebenen Bedrohungsmodell ist das akzeptiert, sollte aber bekannt sein: Token nur in einem vertrauenswürdigen Netz setzen.
Sicherheitsprobleme bitte vertraulich melden — kein öffentliches GitHub-Issue für eine Schwachstelle anlegen.
- E-Mail: info@selfcoder.de
- Bitte angeben: betroffene Version, Beschreibung des Problems, Schritte zur Reproduktion (ein Proof of Concept hilft).
- Du erhältst so schnell wie möglich eine Eingangsbestätigung. Wir bestätigen die Meldung und stimmen einen Zeitplan für Fix/Mitigation mit dir ab.
Bitte gib uns vor einer Veröffentlichung ausreichend Zeit für einen Fix (koordinierte/verantwortliche Offenlegung).
selfstream ist für den Betrieb in einem vertrauenswürdigen Heim-/Lab-Netzwerk gedacht. Das Admin-Panel (Port 8080) sollte nicht direkt aus dem Internet erreichbar sein. Probleme, die ein bereits kompromittiertes LAN oder ein direkt aus dem Internet erreichbares Admin-Panel voraussetzen, liegen außerhalb des normalen Bedrohungsmodells — Meldungen sind aber trotzdem willkommen.