Skip to content

Security: lynicis/hasir

Security

SECURITY.md

Security Policy

Supported Versions

We currently support the latest stable release of the Hasir platform with security patches.

Version Supported
latest

Older versions receive security patches only if explicitly noted in release announcements.

Reporting a Vulnerability

We take security seriously. If you discover a security vulnerability in Hasir, please report it privately — do not open a public issue.

Contact: me@lynicis.dev

You can expect:

  1. Acknowledgment within 48 hours of your report.
  2. An initial assessment within 5 business days, including whether the issue is accepted as a valid vulnerability and a rough severity estimate.
  3. Regular updates on progress toward a fix, at least every 14 days.
  4. Coordinated disclosure — we will work with you to determine a suitable release date for the fix before public disclosure.

We ask that you:

  • Provide a clear description of the issue, including steps to reproduce.
  • Share any proof-of-concept code or payloads privately.
  • Allow us reasonable time to fix and release before disclosing publicly.

Scope

This policy applies to the Hasir monorepo and its official releases. It does not apply to third-party dependencies — report those to their respective maintainers.

Recognition

We maintain a hall of thanks for researchers who help us improve security. With your permission, we will credit you in release notes for valid, accepted reports.

Thank you for helping keep Hasir and its users safe.

There aren't any published security advisories