1.8 KiB
1.8 KiB
Security Policy
Supported Versions
We release security patches for the latest versions of Hermes Android and Hermes Pair.
| Version | Supported |
|---|---|
| 1.0.x | ✅ |
| < 1.0 | ❌ |
Reporting a Vulnerability
The Hermes team takes the security of our application, user credentials, and network communications seriously.
If you believe you have found a security vulnerability in Hermes Android or Hermes Pair, please report it responsibly:
- Do not disclose the issue publicly in GitHub Issues, Discussions, or pull requests.
- Submit a report via GitHub Private Vulnerability Reporting at GitHub Security Advisories or contact repository maintainers directly.
- Include details:
- Description of the vulnerability.
- Steps to reproduce or proof-of-concept (PoC).
- Affected components (
hermes-androidclient,hermes-pairhelper, token vault, or network layer). - Potential impact.
Response Timeline
- Initial Triage: We aim to acknowledge receipt of vulnerability reports within 48 hours.
- Assessment & Fix: We will provide a status update within 7 days with an assessment of the vulnerability and expected remediation timeline.
- Disclosure: A security advisory and public release notes will be coordinated once a patch is released and tested.
Security Practices
- Hermes Android stores host tokens in Android Keystore / EncryptedSharedPreferences with host isolation.
- Network communications support HTTPS and WSS with token-based authentication and ticket exchange.
hermes-pairgenerates cryptographically random nonces (16-byte CSPRNG) with strict TTL expiration for pairing QR codes.