Sinter connects to hosts over SSH and, with --sudo, changes them as root.
A vulnerability in it can affect every host it manages, so please report
suspected vulnerabilities privately, as described below.
Sinter has a single release line. Security fixes are made on main and
shipped in a new release; earlier releases are not patched. Only the
latest release receives
security fixes, so the fix for a vulnerability in an older version is to
upgrade.
Report it through GitHub's private vulnerability reporting:
- Open https://github.com/hagix9/sinter/security/advisories/new (or Security → Report a vulnerability in this repository).
- Describe the problem. Only you and the repository maintainers can see the report.
Do not report a suspected vulnerability in a public issue, pull request, or discussion.
A vulnerability is anything in this repository that breaks one of Sinter's
security and safety properties
or otherwise lets an attacker gain access or privileges they should not
have. Examples: SSH host-key verification being bypassed, a remote command
having its argv reinterpreted by a shell, a file mutation escaping its trust
boundary, plan or audit changing a target, or a sensitive value appearing
in any output. Ordinary bugs go to the issue tracker
instead; see Contributing.
A useful report includes:
- the Sinter version (
sinter --version) and how it was installed; - the controller OS and the target OS and version;
- the smallest recipe and command line that reproduce the problem;
- what happened, what you expected, and the impact you see;
- whether the problem is already known publicly.
Replace real hostnames, credentials, keys, and tokens with placeholders.
Please do not disclose the vulnerability publicly until a fixed release is available or we have agreed on a disclosure date together.
Sinter is a small project. Reports are handled on a best-effort basis, without a fixed response time. After you report:
- the report is acknowledged, and discussion continues in the private advisory;
- if it is confirmed, the fix is shipped in a new release and a GitHub security advisory is published, crediting you unless you ask otherwise;
- if it is not treated as a vulnerability, you get an explanation, and you may be asked to file it as a public issue instead.