Security policy
Supported versions
| Version | Security fixes |
|---|---|
| Latest release, and the one before it | Yes |
| Older releases and commits | No: fixes ship in a new release only. Update with the installer, see docs/docker.md |
Support covers the latest release and the one before it; a security fix is only ever made in a new release.
Reporting a vulnerability
Please report vulnerabilities in Libris Translate privately, never in a public issue.
Email licences@libris-translate.com with a subject beginning with
[SECURITY]. Do not open a public issue or paste the report into a public discussion. If ordinary email is not
appropriate for the details, use it only to request another private exchange before sending the reproduction.
Include the affected version or commit, how Libris is deployed, what you expected and what happened, and a minimal reproduction with synthetic data. Describe the likely impact and provide a way to reach you for follow-up. Remove secrets, cookies and book content from logs and screenshots.
Every report is acknowledged within two business days (Paris time), whatever the plan; that is a target, not a contractual commitment. Fixes are released as soon as practical. For anything that is not a vulnerability, write to support@libris-translate.com.
Running Libris safely
- Keep PostgreSQL and the optional Codex bridge on the private Compose network; only the web application should publish a port.
- Use HTTPS for any access beyond the local machine, and keep
COOKIE_SECURE=true(the default) behind it. - Protect the
.envfile and back it up with the data: losingSECRET_KEYmakes saved provider credentials unreadable. - Translation sends the passages being processed to the providers you configure. Choose them according to your privacy requirements.
The security design (authentication, sessions, tokens, isolation between users, container hardening) is described in docs/architecture.md; installation hardening is in docs/docker.md and docs/configuration.md.