Security advisories
Public record of fixed security issues in Roasthubs products (CRA Annex I Part II §4 and §8). The same channels are used to inform users under Art. 14(8) when there is an actively exploited vulnerability or a severe incident — including when users must act before a patch exists.
Canonical machine record: GitHub Security Advisories on roasthubs/roasthubs-os. This page is the customer-readable index.
To report an unfixed vulnerability, do not use this page. Use vulnerability disclosure (info@roasthubs.com, monitored).
Published advisories
No public advisories have been published yet.
| ID | Date | Severity | Affected | Fixed in | Summary |
|---|---|---|---|---|---|
| — | — | — | — | — | — |
When a GitHub Security Advisory is published, a row is added here (GHSA/CVE links, affected versions, fixed version, how to apply the update).
How we tell users (Art. 14(8))
- Email to known operator contacts of impacted sites.
- GitHub Security Advisory (draft while coordinating; publish when the fix is available, or earlier for mitigation).
- This page.
- Follow-up on info@roasthubs.com.
See incident and vulnerability reporting for Art. 14 clocks and the ENISA SRP. See secure updates for how edge hosts pull a signed image.