| Version | Supported |
|---|---|
| latest | � |
| < latest | � |
If you discover a security vulnerability, please report it to security@hikari-group.tech.
Do NOT open a public issue for security vulnerabilities.
We will:
- Acknowledge receipt within 48 hours
- Investigate and assess severity
- Provide a fix timeline
- Credit you in the fix release (if desired)
- All public repositories under HIKARI-GROUP
- No proprietary code, private data, or production systems
- No automated scanning without prior agreement
- Social engineering
- Physical attacks
- Denial of service
- Automated vulnerability scanners
- Vulnerabilities in third-party dependencies (report to upstream)
- Secrets via environment variables (never in code)
- Input validation on all external data
- Authentication required for sensitive actions
- Regular dependency audits
- OAuth scopes minimized to what's needed