The Hive maintainers take the security of this project seriously. Thank you for helping keep Hive and its users safe by disclosing vulnerabilities responsibly.
Please do not report security vulnerabilities through public GitHub issues, pull requests, or discussions. Public reports expose users to the very weakness being reported before a fix is available.
Instead, use private vulnerability reporting:
- Go to the repository's Security tab.
- Click Report a vulnerability (GitHub's private security advisory flow).
- Provide a description of the issue and how to reproduce it.
If private reporting is unavailable to you for any reason, contact a repository maintainer directly rather than opening a public issue.
Please include, as much as you can:
- The affected component, branch, and commit (or version).
- A description of the vulnerability and its potential impact.
- Step-by-step instructions to reproduce it.
- Any proof-of-concept, logs, or configuration that help us confirm it.
- Acknowledgement: we aim to acknowledge your report within 5 business days.
- Assessment: we will investigate, confirm the issue, and keep you informed of our progress.
- Fix and disclosure: we will work on a fix and coordinate a disclosure timeline with you. We ask that you give us a reasonable opportunity to remediate before any public disclosure.
- Credit: with your permission, we are happy to credit you for the report.
Reports about the code in this repository are in scope. When in doubt, report it privately and let us triage — we would rather hear about a non-issue than miss a real one.
Thank you for contributing to the security of Hive.