Skip to content

Security: shmaplex/nous

SECURITY.md

Security Policy for Nous

Supported Versions

Nous is currently in initial launch (v1.0.0). Security updates and support will be provided for this version. Future releases will be versioned incrementally, and this policy will be updated accordingly.

Version Supported
1.0.0
< 1.0.0

ℹ️ Only version 1.0.0 receives active security support. Users are encouraged to stay on this version for initial launch stability.

Reporting a Vulnerability

If you discover a potential security vulnerability in Nous, please follow these steps:

  1. Report privately: Email the security team at team@shmaplex.com.

    • Do not post vulnerabilities publicly (e.g., on GitHub) before a fix is released.
  2. Provide details:

    • Version of Nous affected
    • Description of the vulnerability
    • Steps to reproduce
    • Any proof-of-concept code or screenshots
  3. Acknowledgment & response:

    • The community shall aim to acknowledge all reports within 48 hours.
    • You will receive updates on the status of the report and planned mitigation.
  4. Resolution:

    • Confirmed vulnerabilities will be patched in the next release.
    • Users of v1.0.0 will be notified of fixes and recommended updates.
  5. Responsible disclosure: Please keep reported vulnerabilities confidential until a fix has been publicly released.

There aren’t any published security advisories