Skip to content

Security: dev-dingyi/Homarus

Security

SECURITY.md

Security Policy

Homarus is a memory-system project. Memory poisoning, prompt injection, provenance bypass, privacy leakage, and unsafe retrieval behavior are in scope.

Reporting Vulnerabilities

Please do not open a public issue for an exploitable vulnerability. Use GitHub private vulnerability reporting when enabled, or contact the maintainers through the security contact listed in the repository profile.

Include:

  • Affected document, component, or proposed implementation area.
  • Reproduction steps or a minimal proof of concept.
  • Expected impact.
  • Suggested mitigation, if known.

Public Security Research

Research issues that do not expose a working exploit may be discussed publicly. Examples include threat-model gaps, benchmark methodology, paper summaries, and defense design proposals.

Current Status

This repository currently contains documentation and reference submodules only. No production implementation is present yet. Security reports are still welcome for unsafe design assumptions, misleading threat claims, or publication risks.

There aren't any published security advisories