We take security seriously. If you discover a security vulnerability in any HERMES 11 project, please do not open a public issue or pull request.
Instead, report it privately by emailing the maintainers at:
security@hermes11.dev (placeholder — replace with your real address)
Please include in your report:
- The affected repository and file(s).
- A description of the vulnerability and its potential impact.
- Steps to reproduce, if available.
We aim to acknowledge reports within 5 business days and will keep you informed of progress toward a fix.
Until our projects reach their first stable release, only the latest commit on the default branch is supported for security fixes.
| Project | Supported |
|---|---|
| pre-release | ❌ Not yet supported |
| latest default | ✅ Supported |
We will credit researchers who report issues responsibly (with your consent) and will coordinate public disclosure once a fix is available.