Dibs handles hub session cookies, bearer tokens, LLM/STT API keys and private ideas. Thank you for helping keep Dibs and its users safe by disclosing vulnerabilities responsibly.
Only the latest main branch and the latest container image
(ghcr.io/hivecommons/dibs:latest) receive security fixes.
Please do not report security vulnerabilities through public GitHub issues, pull requests, or discussions. Public reports expose users to the weakness before a fix is available.
Instead, use private vulnerability reporting:
- Go to the repository's Security tab.
- Click Report a vulnerability (GitHub's private security advisory flow).
- Describe the issue and how to reproduce it.
If private reporting is unavailable to you for any reason, contact a repository maintainer directly rather than opening a public issue.
Please include, as much as you can:
- The affected component, branch, and commit (or image tag).
- A description of the vulnerability and its potential impact.
- Step-by-step instructions to reproduce it.
- Any proof-of-concept, logs, or configuration that help us confirm it.
- Acknowledgement: we aim to acknowledge your report within 5 business days.
- Assessment: we will investigate, confirm the issue, and keep you informed.
- Fix and disclosure: we will work on a fix and coordinate a disclosure timeline with you. Please give us a reasonable opportunity to remediate before any public disclosure.
- Credit: with your permission, we are happy to credit you for the report.
Reports about the code in this repository are in scope. When in doubt, report it privately and let us triage.