The following versions of Hive currently receive security updates.
| Version | Supported |
|---|---|
| Latest release | ✅ |
Development (main) |
✅ |
| Older releases | ❌ |
If you discover a security vulnerability, please do not open a public GitHub issue.
Instead, use GitHub's private security reporting feature:
https://github.com/LaraPire/hive/security/advisories/new
If that is unavailable, contact the maintainers privately and include:
- A clear description of the vulnerability
- Steps to reproduce
- Potential impact
- Proof of concept (if applicable)
- Suggested mitigation (optional)
After receiving a report, we will:
- Acknowledge receipt as soon as possible.
- Verify and assess the issue.
- Work on a fix.
- Release a security update when appropriate.
- Credit the reporter when disclosure is agreed upon.
Security reports may include issues related to:
- Runtime management
- Project creation
- File system access
- Process execution
- Docker integration
- Network features
- Tunnel functionality
- Dependency management
- Authentication or authorization
- Sensitive data exposure
The following are generally considered out of scope:
- Issues requiring physical access.
- Social engineering attacks.
- Vulnerabilities in third-party software.
- Self-XSS.
- Reports without a reproducible proof of concept.
Please allow reasonable time for a fix before publicly disclosing a vulnerability.
Thank you for helping keep Hive secure. 🐝