Laradock is rolling-release: only the latest master is supported. Before reporting a vulnerability, please make sure you are on the latest commit and have rebuilt your images.
Please report security vulnerabilities privately — do not open a public issue.
- Preferred: open a private security advisory on GitHub, or
- Email: the maintainer at mahmoud@zalt.me.
Please include steps to reproduce and the affected component (for example, a specific service Dockerfile or .env option). We will acknowledge your report as soon as possible and keep you informed as we work on a fix.