Only the current stable release receives security updates. Older versions are unsupported — please upgrade.
| Version | Supported |
|---|---|
| 3.3.x | ✅ Current stable |
| 3.2.x | |
| 3.1.x | |
| 3.0.x | ❌ No longer supported |
| < 3.0 | ❌ No longer supported |
Please do not open a public GitHub issue for security vulnerabilities.
Report vulnerabilities privately via one of the following methods:
- GitHub Private Security Advisory: Security tab → Report a vulnerability
- Email: Contact the maintainer directly through the profile linked on the repository.
- A description of the vulnerability and its potential impact.
- Steps to reproduce (script version, OS, configuration snippet if relevant).
- Any suggested fix or mitigation if you have one.
| Milestone | Timeframe |
|---|---|
| Acknowledgement | Within 48 hours |
| Initial assessment | Within 5 business days |
| Patch release (if confirmed) | Within 14 days for critical; 30 days for moderate |
| Public disclosure | Coordinated with the reporter after a patch is available |
Vulnerabilities that are accepted will result in a patched release and a public advisory. Vulnerabilities that are declined will receive a clear explanation.
This policy covers enhanced_automated_backups.sh and the supporting
configuration, systemd units, and hook examples in this repository.
Third-party tools (BorgBackup, rclone, rsync, inotify-tools) have their own
security policies.