Security policy
Meerkat runs with access to the Docker socket and, in the default Compose file, with privileged: true and host networking. A vulnerability in Meerkat can therefore mean root on the host, so please report problems privately.
Reporting a vulnerability
Use GitHub private vulnerability reporting. Please do not open a public issue for security problems.
Include the affected version or image tag, how to reproduce the problem, and the impact you expect. You should get an acknowledgement within 7 days.
Supported versions
Only the latest release receives security fixes while the project is pre-1.0.
Hardening recommendations
- Set
MEERKAT_ACTION_TOKENto a long random value. If you do not set one, Meerkat generates one on first start, logs it once, and stores it instate/state.json. Action endpoints always require a token. - Do not expose ports
8710or8711to the internet. Put them behind a reverse proxy with authentication or a VPN. - Read-only endpoints (
/api/status,/metrics, ...) are currently unauthenticated and reveal container names and network details. - Set
actions.enabled: falseif you only want monitoring and no remote repairs. - Keep
meerkatinactions.blocked_containers.