Please report security issues privately by opening a GitHub security advisory or contacting the project maintainer directly. Do not publish exploit details before a fix is available.
The first public release line is 1.x.
- Set
ROUNDS_DISABLE_SIGNUPS=trueandVITE_DISABLE_SIGNUPS=truefor invite-only deployments. - Set strong
PB_ADMIN_EMAILandPB_ADMIN_PASSWORDonly through deployment secrets or a private.envfile. - Restrict
CORS_ALLOW_ORIGINSto your production domain. - Back up the PocketBase volume regularly.