We take security vulnerabilities very seriously. If you discover a security vulnerability in Harbor, please email us at security@harborextension.dev or create a private security advisory.
Please do not publicly disclose the vulnerability until we have had a chance to address it.
When reporting a vulnerability, please include:
- Description of the vulnerability
- Steps to reproduce
- Potential impact
- Suggested fix (if you have one)
- Keep the extension updated to the latest version
- Only enable the extension when needed
- Review permissions requested by the extension
- Use strong API keys and tokens
- Don't share your API keys in public repositories
- Always use HTTPS for API communications
- Validate and sanitize all user input
- Store sensitive data securely
- Follow the principle of least privilege
- Keep dependencies updated
- Review code before merging
- Use Content Security Policy (CSP) headers
- Implement proper error handling
- Content Security Policy (CSP) enforcement
- Secure API communication with encryption
- Input validation and sanitization
- No storage of sensitive credentials in plain text
- Regular security audits of dependencies
| Version | Supported |
|---|---|
| 1.0.x | Yes |
None currently known. Please report any security issues responsibly.