Security announcements
Licensing Akka libraries ensures organizations that the versions of Akka libraries they are running in production will have all the latest known vulnerabilities patched and maintain compliance with SOC 2 standards. See Akka Compliance for more information.
Receiving Security Advisories
The best way to receive any and all security announcements is to subscribe to the Akka security list.
The mailing list is very low traffic, and receives notifications only after security reports have been managed by the core team and fixes are publicly available. |
Reporting Vulnerabilities
We strongly encourage people to report such problems to our private security mailing list first, before disclosing them in a public forum.
Following best-practice, we strongly encourage anyone to report potential security vulnerabilities to [email protected]
before disclosing them in a public forum like the mailing list or as a GitHub issue.
Reports to this email address will be handled by our security team, who will work together with you to ensure that a fix can be provided without delay.
Fixed Security Vulnerabilities
This list doesn’t include vulnerabilities in external dependencies of Akka. See Akka Compliance for more information and full list of CVEs from dependencies addressed through upgrades in Akka libraries.
Security aspects when building systems with Akka
Akka libraries supports building secure systems that assume Zero Trust to their environment. Learn more about building secure systems with Akka: Implementing Zero Trust with Akka.