Skip to content

Security: NrgXnat/docker-images

Security

SECURITY.md

Security Policy

This policy applies to all repositories in the NrgXnat organization, including XNAT core, XNAT plugins, and related tools, unless a repository provides its own SECURITY.md.

Supported Versions

XNAT core

Version Supported
1.10.x ✅
1.9.3.x ⚠️
< 1.9.3 ❌

Fixes for 1.9.3.x are provided at the XNAT team's discretion, typically for critical or high-severity issues. For the latest features and fixes, we recommend upgrading to the latest release.

XNAT plugins

For each plugin, only the latest release is supported. Security fixes are delivered in a new plugin release rather than backported to older plugin versions. To receive a fix, upgrade to the latest release of the plugin that is compatible with a supported XNAT version.

Reporting a Vulnerability

Please do not report security vulnerabilities through public GitHub issues, discussions, or pull requests.

Private vulnerability reporting (preferred)

Report the issue privately in the repository where the vulnerability exists:

  1. Go to the affected repository (for example, NrgXnat/xnat for XNAT core, or the repository for the affected plugin).
  2. Open the Security tab.
  3. Click Report a vulnerability.

If you're not sure which repository is affected, report it in NrgXnat/xnat.

Email

Prefer email? Write to [email protected] instead. Use email if you need to attach logs, screenshots, or other files, or if the affected repository is archived or doesn't offer the Report a vulnerability button.

What to Include

Please include a detailed description of the issue, steps to reproduce it, its potential impact, and your environment:

  • Affected repository or plugin
  • XNAT version
  • Plugin versions
  • Tomcat version
  • Postgres version
  • OS version
  • Browser version

Do not include protected health information (PHI) or real subject data in your report, logs, or screenshots. Please redact or de-identify them first.

Thanks for helping us keep XNAT secure!

There aren't any published security advisories