Skip to content

Security: MTabuadaM/vSphere

Security

SECURITY.md

Security Policy

πŸ”’ Supported Versions

We actively maintain and support the latest version of the VMware Virtualization Optimization Toolkit.
Older versions may not receive security updates.

Version Supported
v1.x βœ…
< v1.0 ❌

πŸ›‘οΈ Reporting a Vulnerability

If you discover a security vulnerability in this project:

  1. Do not open a public issue.
    Security concerns should be reported privately to avoid exposing risks.

  2. Contact the maintainer directly:

  3. Provide as much detail as possible:

    • Steps to reproduce the issue
    • Affected scripts or modules
    • Potential impact (e.g., data loss, privilege escalation)
    • Suggested mitigation if available

βš–οΈ Security Best Practices

When using or adapting this toolkit:

  • Always run scripts in a controlled environment before production.
  • Use least privilege accounts when connecting to vCenter.
  • Rotate credentials regularly and avoid hardcoding passwords in scripts.
  • Monitor logs for unusual activity after applying automation.
  • Keep VMware and PowerCLI updated to the latest stable versions.

πŸ“œ License & Responsibility

This project is licensed under GNU GPL v3.
While the toolkit is provided "as is," we take security seriously and will address reported vulnerabilities promptly.


Maintainer: Mario Tabuada Mussio
Cloud Solution Architect | IT Technical Manager

There aren't any published security advisories