Skip to content

Security: kafkade/herald

SECURITY.md

Security Policy

Supported Versions

Version Supported
latest

Reporting a Vulnerability

If you discover a security vulnerability in Herald, please report it responsibly:

  1. Do NOT open a public issue.
  2. Open a private security advisory on GitHub.
  3. Include:
    • Description of the vulnerability
    • Steps to reproduce
    • Potential impact
    • Suggested fix (if any)

You should receive an acknowledgment within 48 hours. We will work with you to understand the issue and coordinate a fix before any public disclosure.

Scope

This policy covers:

  • The Herald server (herald-server)
  • The CLI viewer (herald-cli)
  • The web viewer (herald-web)
  • Official container images

Out of scope:

  • Third-party plugins or forks
  • Issues in upstream dependencies (report those to the dependency maintainers)

There aren't any published security advisories