- versions.env pins podman, conmon, crun, netavark, aardvark-dns, passt, and fuse-overlayfs to verified upstream source checksums; SlackBuild recipes, scripts/build-packages.sh, checksums.sh, release.sh, and update-versions.sh implement the reproducible pipeline; GitHub Actions workflows build in a Slackware container and publish releases without committing any binaries. - plugin/podman.plg installs/updates/removes all eight packages (the seven components plus the plugin's own unraid-podman scaffolding package) via upgradepkg, using the official Unraid array-event hook mechanism (event/disks_mounted, event/stopping) instead of editing /boot/config/go. rc.podman and the sbin/ helper scripts implement storage creation, config seeding/sync, preflight checks, autostart with per-container Safe-Mode, and package verify/update/rollback. - webui/plugins/podman implements the Dashboard, Containers, Pods, Images, Volumes, Networks, Logs, Terminal, Compose, and Settings panels against the approved mockup (webui/mockups/prototype.html), talking to podman system service exclusively via PodmanClient.php (libpod REST API over the Unix socket), with two documented exceptions: Terminal's one-shot exec model and Compose's use of the podman compose CLI, since libpod has no REST equivalent for either. - docs/ARCHITECTURE.md and docs/ROADMAP.md record the design decisions and honest current status (syntax-checked, unit- and integration-tested against fake sockets/servers; not yet run against a real Unraid/Podman/Slackware system). Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
1.4 KiB
1.4 KiB
Security Policy
Threat model context
This plugin runs rootful Podman. Its API socket (/var/run/podman/podman.sock)
is root-equivalent on the host, in the same way Docker's docker.sock is. See
docs/ARCHITECTURE.md
for the full rationale. Treat any bug that affects socket permissions, WebUI
authentication, or container-to-host isolation as security-sensitive by default.
Reporting a vulnerability
Please do not open a public GitHub issue for security vulnerabilities.
Instead, use one of:
- GitHub private security advisories for this repository, or
- Email the maintainers at
security@OWNER-DOMAIN(placeholder — update once a contact address exists).
Please include:
- A description of the issue and its potential impact.
- Steps to reproduce (Unraid version, plugin version, storage backend).
- Whether the issue requires local access, network access, or a malicious container image to trigger.
Supported versions
This project has not yet cut a stable release. Until a 1.0.0 release, only the
latest main branch / most recent tag is supported with security fixes.
Disclosure process
We aim to acknowledge reports within 5 business days and to agree on a coordinated disclosure timeline before any public write-up.