Skip to content

Security: xxraincandyxx/raintop

Security

SECURITY.md

Security policy

Reporting a vulnerability

Please do not open a public issue for a suspected vulnerability. Report it privately to the repository maintainers with the affected version, reproduction steps, and potential impact. Avoid including real credentials or private host data.

Supported versions

Until the first stable release, security fixes are applied to the latest commit on the default branch.

Security boundaries

Raintop relies on OpenSSH for authentication and host identity. It stores only device names and SSH destinations in the OS application-config directory. It does not store credentials or send telemetry to a service. Remote command output is treated as untrusted input and normalized before it crosses into the UI.

There aren't any published security advisories