Skip to content

Security: btouchard/herald

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

If you discover a security vulnerability in Herald, please report it responsibly.

Email: security@kolapsis.com

Please include:

  • Description of the vulnerability
  • Steps to reproduce
  • Potential impact
  • Suggested fix (if any)

Response Timeline

  • Acknowledgment: within 48 hours
  • Initial assessment: within 1 week
  • Fix and disclosure: coordinated with reporter

Scope

  • Herald server (Go binary)
  • OAuth 2.1 implementation
  • MCP protocol handling
  • SQLite storage
  • Configuration parsing

Out of Scope

  • Claude Code CLI vulnerabilities (report to Anthropic)
  • Infrastructure misconfigurations
  • Social engineering

Supported Versions

Version Supported
Latest release
Previous release Security fixes only
Older

There aren’t any published security advisories