Skip to content

Security: HiveSofts/hive-cli

Security

.github/SECURITY.md

Security Policy

Supported Versions

The following versions of Hive currently receive security updates.

Version Supported
Latest release
Development (main)
Older releases

Reporting a Vulnerability

If you discover a security vulnerability, please do not open a public GitHub issue.

Instead, use GitHub's private security reporting feature:

https://github.com/LaraPire/hive/security/advisories/new

If that is unavailable, contact the maintainers privately and include:

  • A clear description of the vulnerability
  • Steps to reproduce
  • Potential impact
  • Proof of concept (if applicable)
  • Suggested mitigation (optional)

Response Process

After receiving a report, we will:

  1. Acknowledge receipt as soon as possible.
  2. Verify and assess the issue.
  3. Work on a fix.
  4. Release a security update when appropriate.
  5. Credit the reporter when disclosure is agreed upon.

Scope

Security reports may include issues related to:

  • Runtime management
  • Project creation
  • File system access
  • Process execution
  • Docker integration
  • Network features
  • Tunnel functionality
  • Dependency management
  • Authentication or authorization
  • Sensitive data exposure

Out of Scope

The following are generally considered out of scope:

  • Issues requiring physical access.
  • Social engineering attacks.
  • Vulnerabilities in third-party software.
  • Self-XSS.
  • Reports without a reproducible proof of concept.

Responsible Disclosure

Please allow reasonable time for a fix before publicly disclosing a vulnerability.

Thank you for helping keep Hive secure. 🐝

There aren't any published security advisories