Skip to content

Security: itamaesanorg/pylaros

Security

SECURITY.md

Security Policy

Final decision, choice of Arch Linux

While selecting a base image for our Docker containers, it is essential to consider not just security vulnerabilities but also performance, flexibility, and a lean environment. In this context, Arch Linux emerges as a superior choice over other Linux distributions. Despite its vulnerability, Arch offers a rolling release system, ensuring that users always have the latest software versions without the need for extensive upgrades. This results in a more streamlined, up-to-date, and performance-optimized system. Moreover, the Arch User Repository (AUR) provides a vast collection of user-submitted packages, further enhancing its adaptability and feature set. While the CVE-2023-29403 exploitability score for Arch might be a concern, it's worth noting that the Arch community is highly active, often leading to rapid patches and updates. This proactive approach, combined with the user-centric philosophy of Arch, ensures a balance between cutting-edge performance and security.

Supported Versions

Distro Version Supported Latest
Linux Arch

Reporting a Vulnerability

gh is installed. Version: gh version 2.37.0 (2023-10-17) rustc is installed. Version: rustc 1.73.0 (cc66ad468 2023-10-03) (Arch Linux rust 1:1.73.0-1) python is installed. Version: Python 3.11.5 node is installed. Version: v20.9.0 lazygit is installed. Version: commit=v0.40.2, build date=2023-08-12T17:47:33Z, build source=binaryRelease, version=0.40.2, os=linux, arch=amd64, git version=2.42.0 nvim is installed. Version: NVIM v0.9.4 psql is installed. Version: psql (PostgreSQL) 15.4 nano is installed. Version: GNU nano, version 7.2 vim is installed. Version: VIM - Vi IMproved 9.0 (2022 Jun 28, compiled Oct 11 2023 19:17:46) make is installed. Version: GNU Make 4.4.1 gcc is installed. Version: gcc (GCC) 13.2.1 20230801 wget is installed. Version: GNU Wget 1.21.4 built on linux-gnu. curl is installed. Version: curl 8.4.0 (x86_64-pc-linux-gnu) libcurl/8.4.0 OpenSSL/3.1.4 zlib/1.3 brotli/1.1.0 zstd/1.5.5 libidn2/2.3.4 libpsl/0.21.2 (+libidn2/2.3.4) libssh2/1.11.0 nghttp2/1.57.0 ufw is installed. Version: ufw 0.36.2 iptables is installed. Version: iptables v1.8.9 (legacy) zip is installed. Version: Copyright (c) 1990-2008 Info-ZIP - Type 'zip "-L"' for software license. unzip is installed. Version: caution: both -n and -o specified; ignoring -o git is installed. Version: git version 2.42.0 neofetch is installed. Version: Neofetch 7.1.0 fc-list is installed. Version: fontconfig version 2.14.2 zsh is installed. Version: zsh 5.9 (x86_64-pc-linux-gnu) pnpm is installed. Version: 8.9.2 yarn is installed. Version: 1.22.19 npm is installed. Version: 10.2.1

There aren’t any published security advisories