Security
Report vulnerabilities and verify kftray release artifacts, SBOMs and build provenance.
Report vulnerabilities privately and verify release artifacts before using them. See the security model for runtime credentials, network binding and elevated permissions.
Report a vulnerability
Don't report security vulnerabilities through public GitHub issues. Use GitHub Private Vulnerability Reporting instead. You'll get a response within 48 hours.
Include:
- A description of the vulnerability
- Steps to reproduce
- Affected versions
- Potential impact
The maintainers coordinate disclosure timing with reporters and prefer at least 90 days before public disclosure.
Supported versions
Security fixes target the latest stable release. Update to that release before checking whether a reported vulnerability affects your installation.
Release scanning
Releases are blocked if the scan finds critical or high severity vulnerabilities. The release workflow runs Grype against the kftray SBOM, the kftui SBOM and the kftray-server image before it publishes.
To run the same scan locally, use the mise task:
mise run sbom:scan-allThe task builds the SBOMs for kftray, kftui and kftray-server, scans each one and fails on high or critical findings. It writes vuln-report-*.json and sbom-*.cdx.json files in the repository root. mise run precommit runs it too. See Development for the other tasks.
Renovate opens the dependency updates, including the pinned versions of Syft and Grype in .mise.toml.
Security artifacts
Each release includes an SBOM, a Cosign bundle and a vulnerability report for each artifact. The SBOMs use the CycloneDX format. The mise tasks build them with Syft, cargo-cyclonedx and sbomasm.
| Artifact | SBOM | Bundle | Vulnerability report |
|---|---|---|---|
kftray (desktop) | sbom-kftray.cdx.json | sbom-kftray.cdx.json.bundle.json | vuln-report-kftray.json |
kftui (terminal) | sbom-kftui.cdx.json | sbom-kftui.cdx.json.bundle.json | vuln-report-kftui.json |
kftray-server (Docker) | sbom-kftray-server.cdx.json | sbom-kftray-server.cdx.json.bundle.json | vuln-report-kftray-server.json |
Two more files cover all artifacts:
| File | Description |
|---|---|
default.vex.openvex.json | VEX (vulnerability exploitability) assessments used to suppress findings |
default.vex.openvex.json.bundle.json | Cosign bundle for the VEX document (signature and certificate) |
The links point to the latest release. Replace latest/download with download/<tag> for a specific version.
Verify release artifacts
You need the GitHub CLI for attestations and Cosign for SBOMs and VEX.
Build provenance
The release workflow creates GitHub build provenance attestations for the release artifacts and the container image. Check them with gh attestation verify:
Replace <version> with the downloaded AppImage's version.
# Docker image
gh attestation verify oci://ghcr.io/hcavarsan/kftray-server:latest --owner hcavarsan
# CLI binary
gh attestation verify kftui_linux_amd64.tar.gz --owner hcavarsan
# Desktop app
gh attestation verify 'kftray_<version>_amd64.AppImage' --owner hcavarsanSBOM signatures
The SBOMs and the VEX document are signed with Cosign keyless signing and the v3 bundle format. This example verifies the kftray SBOM:
curl -LO https://github.com/hcavarsan/kftray/releases/latest/download/sbom-kftray.cdx.json
curl -LO https://github.com/hcavarsan/kftray/releases/latest/download/sbom-kftray.cdx.json.bundle.json
cosign verify-blob \
--bundle sbom-kftray.cdx.json.bundle.json \
--certificate-identity-regexp "https://github.com/hcavarsan/kftray" \
--certificate-oidc-issuer "https://token.actions.githubusercontent.com" \
sbom-kftray.cdx.jsonReplace kftray with kftui or kftray-server to verify the other SBOMs.
VEX signature
curl -LO https://github.com/hcavarsan/kftray/releases/latest/download/default.vex.openvex.json
curl -LO https://github.com/hcavarsan/kftray/releases/latest/download/default.vex.openvex.json.bundle.json
cosign verify-blob \
--bundle default.vex.openvex.json.bundle.json \
--certificate-identity-regexp "https://github.com/hcavarsan/kftray" \
--certificate-oidc-issuer "https://token.actions.githubusercontent.com" \
default.vex.openvex.jsonLinux packages
The Debian, Ubuntu, Fedora, openSUSE and Arch Linux packages come from the openSUSE Build Service and are signed with the project key of home:hencavarsan:kftray. The .repo files reference that key, the apt source pins it with signed-by and pacman trusts it after pacman-key --lsign-key. See Installation and Linux packaging.
Container image
The kftray-server image has these properties:
| Property | Value |
|---|---|
| Base image | scratch, with only the statically linked kftray-server binary |
| User | Non-root (65532:65532) |
| Shell | None |
| Architectures | linux/amd64, linux/arm64 |
See Relay Server for the image configuration.
Build integrity
The release workflow builds on GitHub Actions hosted runners and generates provenance with actions/attest-build-provenance. GitHub creates the attestation with its Sigstore-based attestation service. The project documents this setup as meeting SLSA Level 2 build requirements:
| Requirement | Evidence |
|---|---|
| Build service | GitHub Actions (hosted runners) |
| Signed provenance | actions/attest-build-provenance |
| Non-forgeable | GitHub's Sigstore-based attestation |
| Service-generated | Provenance generated by GitHub, not by the user |
Acknowledgments
The maintainers acknowledge reporters after coordinated disclosure.