This Security Policy explains how to responsibly report vulnerabilities in DBX, an open-source tool used for automated database backups, restores, scheduling, and cloud uploads. Because DBX interacts with sensitive data sources, security and responsible disclosure are extremely important.
| Version | Security Support |
|---|---|
| 0.1.x | ✔ Active |
Older versions no longer receive patches.
If you find a bug that could affect:
- Database credentials
- Backup files
- Cloud uploads (AWS S3 / GCS / Azure Blob)
- Logging or scheduling
- CLI execution or system-level interactions
Do NOT disclose it publicly.
Instead, email:
Please include:
- A clear description
- Steps to reproduce
- Potential impact
- Proof-of-concept (if possible)
All reports are reviewed within 48 hours.
We follow industry-standard responsible disclosure practices:
- You report privately
- We investigate
- We release a fix
- You may be credited (optional)
Thank you for helping keep DBX secure for thousands of developers and database administrators.