Skip to content

Security: danicyber1/agent-semantic-protocol

Security

SECURITY.md

Security Policy

Supported Versions

We actively maintain the following versions of the Agent Semantic Protocol:

Version Supported
v0.1 ✅ Fully supported
v0.2 ✅ Fully supported
< v0.1 ❌ No longer supported

Reporting a Vulnerability

If you discover a security vulnerability, please report it privately. Do not disclose it as a public issue.

How to Report

  1. Email: Send a detailed report to security@agent-semantic-protocol.org.
  2. GitHub Private Advisory: Use GitHub’s private vulnerability reporting feature.

What to Include

  • A detailed description of the vulnerability.
  • Steps to reproduce the issue.
  • Potential impact and severity.
  • Any suggested fixes or patches.

Response Time

We are committed to addressing security issues promptly:

  • Acknowledgment: Within 48 hours.
  • Patch Development: Critical vulnerabilities will be patched within 14 days.
  • Release: A new version will be released with the fix.

Out-of-Scope

The following are not considered security vulnerabilities:

  • Issues in unsupported versions.
  • Vulnerabilities in third-party dependencies (please report these upstream).
  • Misconfigurations in user environments.

Known Security Features

  • Ed25519 Signing: Ensures message authenticity and integrity.
  • Noise Protocol Encryption: Secures transport-level communication.
  • DID Binding: Decentralized identifiers for agent authentication.

Thank you for helping us keep the Agent Semantic Protocol secure! 🌟

There aren’t any published security advisories