Skip to content

Security: phmotad/firememory

Security

SECURITY.md

Security Policy

Supported Versions

Version Supported
0.1.x Yes

Reporting a Vulnerability

Do not open a public GitHub issue for security vulnerabilities.

Send a private report to: phmotad@gmail.com

Include:

  • Description of the vulnerability
  • Steps to reproduce
  • Potential impact
  • Suggested fix if you have one

You will receive an acknowledgment within 48 hours and a status update within 7 days.

Scope

In scope:

  • fmem and fquery CLI binaries
  • FireMemory core engine
  • FireQuery pipeline and MCP server
  • .fbrain file format parsing

Out of scope:

  • Third-party ML models (report to their respective maintainers)
  • OS-level issues

Disclosure Policy

We follow coordinated disclosure. We will work with you to understand and fix the issue before any public announcement.

There aren't any published security advisories