Skip to content

Security: squip/hyperpipe-gateway

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

Do not open a public GitHub issue for security vulnerabilities.

Preferred reporting path:

  1. Use GitHub Private Vulnerability Reporting for this repository if it is enabled.
  2. If private reporting is not available, contact the repository owner privately through GitHub or another private channel you already use with the maintainer.

Please include:

  • affected package or application
  • affected version, commit, or release artifact
  • impact summary
  • reproduction steps or proof of concept
  • any required configuration details
  • logs or screenshots with secrets redacted

Response Expectations

  • initial acknowledgement target: within 5 business days
  • status updates target: at least once every 10 business days while actively triaging

These are targets, not contractual SLAs.

Scope

Priority support applies to:

  • the current default branch in the canonical monorepo
  • the latest published first-party npm packages
  • the latest desktop/TUI release artifacts
  • the latest supported gateway container image and deployment docs

Out-of-date forks, old unpublished snapshots, and modified local builds may be triaged on a best-effort basis only.

Disclosure

Please wait for a coordinated fix or mitigation before disclosing a vulnerability publicly.

This project does not currently advertise a bug bounty program.

There aren’t any published security advisories