| Version | Supported |
|---|---|
| 1.0.x | ✅ |
| < 1.0 | ❌ |
Please do not file public issues for security vulnerabilities.
Instead, please report vulnerabilities by emailing: security@seocho-project.org
Include:
- Description of the vulnerability
- Steps to reproduce (if applicable)
- Potential impact
- Suggested fix (if any)
We will respond within 48 hours and work with you to coordinate disclosure.
- All data lineage information is encrypted at rest
- Neo4j connections use TLS encryption
- Sensitive configuration values use environment variables
- No hardcoded credentials in source code
- Use official base images only
- Regular security scanning with Trivy
- Minimal container images (distroless where possible)
- Non-root user execution
- All services communicate over internal Docker networks
- No exposed ports beyond necessary endpoints
- Rate limiting on API endpoints
- Input validation on all data ingestion points
- Default credentials must be changed in production
- Role-based access for DataHub
- Neo4j authentication enabled
- Regular access reviews
- GitHub Actions security scanning on PRs
- Docker image vulnerability scanning
- Dependency vulnerability checks (Dependabot)
- CodeQL static analysis
- Security review required for new data connectors
- Penetration testing before major releases
- Security architecture review for new features
Seocho is designed to support:
- SOC 2 Type II compliance
- GDPR data lineage requirements
- HIPAA audit trails
- ISO 27001 information security management
# Example override file, not tracked in this repo
services:
dozerdb:
environment:
- NEO4J_dbms_security_procedures_unrestricted=gds.*,apoc.*
- NEO4J_dbms_security_auth__minimum__password__length=12
- NEO4J_dbms_logs_security__level=DEBUG# Generate certificates
openssl req -x509 -newkey rsa:4096 -keyout neo4j.key -out neo4j.crt -days 365 -nodes- Detection: Security alerts from monitoring tools
- Assessment: Impact analysis and severity classification
- Containment: Isolate affected systems
- Recovery: Patch and restore services
- Post-incident: Review and improve security measures
Security patches are released as:
- Critical: Within 24 hours
- High: Within 72 hours
- Medium: Next scheduled release
- Low: Quarterly security updates
Subscribe to security announcements: security@seocho-project.org