Skip to content

Security: iap/builder

SECURITY.md

Security Policy

Reporting a Vulnerability

Security is a top priority for the Hermes builder plugin. If you believe you have found a security vulnerability, please report it to us.

How to Report

  • GitHub Security Advisories: Use the "Report a vulnerability" button on the Security tab
    • This is the primary and monitored channel for security reports
    • GitHub will mediate initial contact and coordinate disclosure

What to Include

Please include the following in your report:

  1. A description of the vulnerability and its impact
  2. Steps to reproduce the issue
  3. Any proof-of-concept code or exploit
  4. Your contact information and availability

Response Timeline

  • We will acknowledge your report within 48 hours
  • We will provide a more detailed response within 7 days
  • We will keep you informed of the progress towards a fix
  • If the vulnerability is confirmed, we will coordinate a disclosure timeline

Scope

This policy covers all repositories under the iap/builder GitHub organization. Please note that this plugin is a guest in the Hermes ecosystem — core Hermes security issues should be reported to NousResearch/hermes-agent instead.

Preferred Languages

We prefer reports in English.