Skip to main content

Security

The Hive maintainers take the security of this project seriously. Thank you for helping keep Hive and its users safe by disclosing vulnerabilities responsibly.

Reporting a Vulnerability​

Please do not report security vulnerabilities through public GitHub issues, pull requests, or discussions. Public reports expose users to the very weakness being reported before a fix is available.

Instead, use private vulnerability reporting:

  1. Go to the repository's Security tab.
  2. Click Report a vulnerability (GitHub's private security advisory flow).
  3. Provide a description of the issue and how to reproduce it.

If private reporting is unavailable to you for any reason, contact a repository maintainer directly rather than opening a public issue.

Please include, as much as you can:

  • The affected component, branch, and commit (or version).
  • A description of the vulnerability and its potential impact.
  • Step-by-step instructions to reproduce it.
  • Any proof-of-concept, logs, or configuration that help us confirm it.

What to Expect​

  • Acknowledgement: we aim to acknowledge your report within 5 business days.
  • Assessment: we will investigate, confirm the issue, and keep you informed of our progress.
  • Fix and disclosure: we will work on a fix and coordinate a disclosure timeline with you. We ask that you give us a reasonable opportunity to remediate before any public disclosure.
  • Credit: with your permission, we are happy to credit you for the report.

Scope​

Reports about the code in this repository are in scope. When in doubt, report it privately and let us triage β€” we would rather hear about a non-issue than miss a real one.

Who Responds​

Reports are handled by the Hive Maintainer Committee β€” see src/docs/security-response.md for who that is today, how a report is triaged and resolved end to end, how membership is decided, and what to do if you don't get a response.

Thank you for contributing to the security of Hive.