We currently support the latest stable release of the Hasir platform with security patches.
| Version | Supported |
|---|---|
| latest | ✅ |
Older versions receive security patches only if explicitly noted in release announcements.
We take security seriously. If you discover a security vulnerability in Hasir, please report it privately — do not open a public issue.
Contact: me@lynicis.dev
You can expect:
- Acknowledgment within 48 hours of your report.
- An initial assessment within 5 business days, including whether the issue is accepted as a valid vulnerability and a rough severity estimate.
- Regular updates on progress toward a fix, at least every 14 days.
- Coordinated disclosure — we will work with you to determine a suitable release date for the fix before public disclosure.
We ask that you:
- Provide a clear description of the issue, including steps to reproduce.
- Share any proof-of-concept code or payloads privately.
- Allow us reasonable time to fix and release before disclosing publicly.
This policy applies to the Hasir monorepo and its official releases. It does not apply to third-party dependencies — report those to their respective maintainers.
We maintain a hall of thanks for researchers who help us improve security. With your permission, we will credit you in release notes for valid, accepted reports.
Thank you for helping keep Hasir and its users safe.