This is the organization-wide default security policy for Hermes Labs.
A repository that publishes its own SECURITY.md overrides this file.
If you discover a security vulnerability in a Hermes Labs repository, please report it privately.
Do not open a public issue for security vulnerabilities.
Email roli@hermes-labs.ai with:
- the repository and version affected,
- a description of the vulnerability,
- steps to reproduce,
- any relevant logs or output.
If the repository has GitHub private vulnerability reporting enabled, you may use that instead.
- Acknowledgment: within 48 hours of your report.
- Assessment: within 7 days we will confirm the issue and outline next steps.
- Fix: we aim to release a patch within 30 days of confirmation.
Security updates are applied to the latest release of each package only.
These repositories are open-source engineering tools. Reports about the behavior of third-party language models, or about findings produced by a tool rather than the tool itself, are handled as ordinary issues rather than as security reports.
Thank you for helping keep Hermes Labs software safe.