Skip to content

Security: gutomezencio/front-proxy

SECURITY.md

Security policy

Supported versions

Only the latest release on npm gets security fixes. Upgrade with npm install -g front-proxy@latest before reporting.

Reporting a vulnerability

Please don't open a public issue. Report it privately through GitHub: open a security advisory.

Include:

  • the front-proxy version (npm ls -g front-proxy), Node version and OS
  • what an attacker can do, and what they need to have or control first
  • steps or a proof of concept to reproduce it

You'll get a reply within 7 days. Once a fix is released, the advisory is published with credit to you, unless you'd rather stay anonymous.

Sensitive areas

front-proxy start runs as root, so these matter most:

  • /etc/hosts edits: anything that could write lines other than the front-proxy block
  • the config and certs in ~/.front-proxy (or $FRONT_PROXY_HOME): file paths, ownership and permissions
  • the admin page on front-proxy.localhost: requests from other sites or non-loopback clients that get through its checks
  • the reverse proxy on ports 80 and 443: routing a request somewhere other than the mapped 127.0.0.1 port

Verifying a release

npm packages are published from GitHub Actions with trusted publishing, so they carry npm provenance:

npm audit signatures

Each GitHub release also has the published tarball and its Sigstore bundle (.sigstore.json). To check a downloaded tarball:

gh attestation verify front-proxy-X.Y.Z.tgz --repo gutomezencio/front-proxy

There aren't any published security advisories