Security fixes are applied to the latest revision on the default branch while SKYACS remains in beta.
Please use GitHub's Private vulnerability reporting feature for this repository. Include the affected revision, deployment topology, reproduction steps, and expected impact. Do not include real subscriber credentials, firmware images, or device exports.
If private reporting is unavailable, contact the repository owner privately before publishing technical details. Please allow reasonable time for triage and remediation.
- Generate a unique
JWT_SECRETof at least 32 random characters. - Generate and back up a unique
PARAMETER_ENCRYPTION_KEY; do not rotate it without re-encrypting existing data. - Rotate or remove
INITIAL_ADMIN_PASSWORDafter the first login. - Terminate browser traffic with HTTPS and restrict API CORS origins.
- Configure
TRUSTED_PROXY_CIDRSandCWMP_TRUSTED_PROXY_CIDRSwith proxy addresses only. - Set
CONNECTION_REQUEST_ALLOWED_CIDRSto the managed CPE destination networks. - Restrict the CWMP listener to known CPE networks; CWMP Basic Auth must only run behind TLS.
- Keep PostgreSQL and the firmware storage directory off the public network.
- Set
firmware_base_urlto an HTTPS endpoint reachable by managed CPEs. - Back up the database before bulk provisioning, reset, or firmware operations.
Signed firmware links are time-limited bearer credentials. They should not be logged by reverse proxies and must only be shared with the intended CPE. Firmware authenticity remains vendor-specific; operators must validate checksums/signatures and compatibility before scheduling an upgrade.