Licensing Akka ensures organizations that the version of Akka they are running in production will have all of the latest known vulnerabilities patched and maintain compliance with SOC 2 standards. See Akka Compliance for more information.
The best way to receive any and all security announcements is to subscribe to the Akka security list.
The mailing list is very low traffic, and receives notifications only after security reports have been managed by the core team and fixes are publicly available.
We strongly encourage people to report such problems to our private security mailing list first, before disclosing them in a public forum.
Following best-practice, we strongly encourage anyone to report potential security vulnerabilities to [email protected] before disclosing them in a public forum like the mailing list or as a GitHub issue.
Reports to this email address will be handled by our security team, who will work together with you to ensure that a fix can be provided without delay.
This list doesn't include vulnerabilities in external dependencies of Akka. See Akka Compliance for more information and full list of CVEs from dependencies addressed through upgrades in Akka libraries.
Akka supports building secure systems that assume Zero Trust to their environment. Learn more about building secure systems with Akka: Implementing Zero Trust with Akka.