About
Why Backportal
European operator team · names later, work first
The morning
It starts the same way every time. An advisory lands. Upstream has already fixed it, in the newest release, the one you are not running. You are two minor versions behind, on a build with your own extensions, your own theme, a cherry-pick from last winter, because the last upgrade took three weeks and broke two things. So you read the advisory, you check whether you are exposed, and then you do the math on how long it will take to upgrade safely. Weeks. And you know that the people on the other side do their math in hours.
We are a European operator team. We have spent years running open-source platforms in production and living with their versioning: forks with a life of their own, extensions that pin you to a line, maintenance releases that stop coming. We have stood in that window more times than we want to count. The window is the problem. Not the CVE, not the upgrade. The time in between.
What changed
Two things moved while we were standing there. Vulnerabilities started being found and weaponized by machines, and the count of published CVEs roughly doubled in two years. And code stopped being the expensive part. A backport that used to cost a senior engineer a day can now be drafted in minutes, if the fix is public and the tests exist.
So the scarce things are no longer the patch. They are the speed to produce it for your exact version line, the proof that it was built and tested and that you were not attacked in the meantime, and a way to do all of that without handing your infrastructure to a vendor. That is what we decided to build.
The name
A backport is a fix carried from where it was made to where it is needed. A portal is the place you come to get it. Backportal is the place where the fix for your line comes from, in hours, with proof. Your fork, patched to upstream.
What we refuse
- To ask for trust we cannot show. Everything that runs on your side is open, and every claim about a fix is verified against the upstream repository before it is published.
- To publish attacks. Our checks confirm the vulnerable condition and stop there. Working exploit chains never leave the lab.
- To charge for code. Five of the six steps are free with your own model key. The hunt is paid, because it needs your logs and someone who knows your deployment. Anything run by us is paid.
- To be loud. Verdicts use the VEX words: fixed, affected, no fix on this line, under investigation. Colors mean one thing each. No shields, no sirens.
Where we are
In preview, and deliberately quiet. The advisories are real and verified, the process runs, and the first tools are being wired one build harness at a time. Names come out with the first customers. If you run something we should cover, ask for it.
Contact
Questions: hello@backportal.dev. Security issues in Backportal itself: security@backportal.dev, see security.txt.
Legal notice
Backportal is an independent project in preview, published by an individual. The site is hosted on Cloudflare Pages (Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA). It sets no cookies and runs no tracking scripts. Alert requests sent by email are stored only to match advisories to the tools and versions you declared and are deleted on request. Publisher details are provided to the host and will be published here when the project leaves preview. Advisory content is based on public sources and is provided without warranty; verify against the upstream project before acting.