Skip to content

Security: itzg/docker-minecraft-bedrock-server

SECURITY.md

Security Policy

Supported Versions

Only the latest release or latest Docker tag receives security updates. If you discover a vulnerability, please test against the latest image version before reporting.

Reporting a Vulnerability

Please do not report security vulnerabilities through public GitHub issues, discussions, or pull requests.

To report a vulnerability privately:

  1. Navigate to the Security tab of this repository.
  2. Select Report a vulnerability to open a private security advisory.

This allows us to review, reproduce, and resolve the issue in a private environment before public disclosure.

Base Image & Non-Runtime Package Scans

  • Unused & Non-Runtime Base OS Packages: Automated scanner reports (e.g., Trivy, Grype) flagging vulnerabilities in base OS packages that are neither executed during container startup nor involved in running the Bedrock server process (e.g., perl or unused system utilities) are considered non-actionable.
  • Base Image Lifecycle: We do not manually patch or update individual OS packages inside the container build (e.g., running apt-get upgrade), nor do we accept PRs to do so. Base OS packages are updated automatically whenever upstream base image updates are pulled during routine builds.
  • Actionable Reports: Security advisories must demonstrate a plausible attack vector or exploit path that directly impacts the Bedrock server execution environment.

Important Expectations & Bug Bounties

  • No Financial Bounties: This is an open-source, community-maintained project. We do not offer financial rewards, gift cards, or monetary bounties for vulnerability reports.
  • Non-Critical & Automated Findings: Reports generated purely by automated scanners (such as generic HTTP headers, low-severity container base image updates, or standard configuration warnings) without a working, practical proof-of-concept specific to this container will generally be closed.

Dependency Upgrades & Pull Requests

We welcome and appreciate community contributions!

If you identify an outdated or vulnerable upstream dependency (such as base packages, system libraries, or underlying binaries), we strongly encourage you to submit a Pull Request directly.

Community-contributed PRs targeting dependency patches are the fastest way to get updates validated, built, and merged into the main release.

There aren't any published security advisories