Skip to content

Security: srinitude/hermes-mastra

Security

SECURITY.md

Security Policy

Supported Versions

We release patches for security vulnerabilities for the following versions:

Version Supported
0.1.x

As the project matures, this table will be updated to reflect actively maintained release lines.

Reporting a Vulnerability

We take security bugs seriously and appreciate your efforts to responsibly disclose them.

Contact: kiren@fantasymetals.com

Please report security vulnerabilities by emailing the address above. Include the following information to help us triage and resolve the issue quickly:

  • Description of the vulnerability and its potential impact.
  • Steps to reproduce the issue, including any proof-of-concept code or configurations.
  • Affected versions, if known.
  • Suggested fix or mitigation, if you have one.

What to Expect

We are committed to timely and transparent communication throughout the reporting process:

Milestone Target
Acknowledgment Within 24 hours of receiving your report.
Initial assessment Within 7 days — we will confirm the vulnerability, determine severity, and outline a remediation plan.
Fix delivered Within 30 days — a patch or mitigation will be released for all supported versions.

If timelines need to be adjusted (e.g., due to complexity or dependency coordination), we will keep you informed and provide updated estimates.

Disclosure Policy

  • Do not publicly disclose the vulnerability before a fix has been released, unless we have explicitly agreed otherwise.
  • We practice coordinated disclosure: once a patch is available, we will publish a security advisory and credit the reporter (see Attribution below).
  • If we are unable to reproduce the issue or determine it is not a security vulnerability, we will explain our reasoning and work with you to reach mutual understanding.
  • We request that reporters allow 90 days from initial report before any independent public disclosure, in accordance with industry-standard responsible disclosure practices.

Attribution

We value and respect the security research community. Reporters who responsibly disclose vulnerabilities will be:

  • Credited in the corresponding security advisory and release notes (unless they prefer to remain anonymous).
  • Listed in a SECURITY.md hall of fame or project-level acknowledgments section as the project grows.

Thank you for helping keep hermes-mastra and its users safe.

There aren’t any published security advisories