Files
ProxmoxVE/SECURITY.md
MickLesk 034bbb1a52 Add Proxmox VE 9.2 support
Expand supported Proxmox VE range to include 9.2. Updated documentation (README.md, SECURITY.md) and adjusted version checks and user messages across scripts (misc/core.func, misc/vm-core.func, tools/pve/post-pve-install.sh and multiple vm/*-vm.sh templates) to accept Proxmox 9.2. Also updated the vm-core regex and post-install checks to allow 9.0–9.2 and updated corresponding error/help messages.
2026-05-21 16:42:12 +02:00

2.1 KiB

Security Policy

Supported Versions

This project currently supports the following versions of Proxmox VE (PVE):

Version Supported
9.2.x
9.1.x
9.0.x
8.4.x
8.3.x Limited support*
8.2.x Limited support*
8.1.x Limited support*
8.0.x Limited support*
< 8.0

*Version 8.0.x - 8.3.x has limited support. Security updates may not be provided for all issues affecting this version.

*Debian 13 Containers may fail to install. You can write var_version=12 before the bash call.


Reporting a Vulnerability

Security vulnerabilities must not be reported publicly to avoid potential exploitation.
Instead, please report them privately via one of the following channels:

When reporting a vulnerability, please provide:

  • A clear description of the issue
  • Steps to reproduce the vulnerability
  • Affected versions or environments
  • (Optional) Suggested fixes or workarounds

Response Process

  1. Acknowledgment

    • We will review and acknowledge your report within 7 business days.
  2. Assessment

    • The maintainers will verify the issue and classify its severity.
    • Depending on impact, a patch may be released immediately or scheduled for the next update.
  3. Resolution

    • Critical security fixes will be prioritized.
    • Non-critical issues may be deferred or declined with an explanation.

Disclaimer

Not all reported issues will be treated as vulnerabilities.
Reports may be declined if they are deemed:

  • Low-risk
  • Out of project scope
  • Conflicting with intended design or architecture

If you have any questions or concerns about this security policy, please reach out to the maintainers through the contact options above.