Skip to content

Security: misofm/dave

SECURITY.md

Security policy

Dave sits between software agents and physical music hardware. Treat any path that can emit device messages, weaken evidence validation, bypass capability checks, or expose captured musical data as security-sensitive.

Reporting a vulnerability

Do not open a public issue for a suspected vulnerability. Use GitHub's private Report a vulnerability flow on this repository. Include the affected commit, the smallest reproducible input or trace, the expected fail-closed behavior, and the observed behavior. Avoid attaching private hardware captures unless they have been scrubbed and are necessary to reproduce the problem.

If private vulnerability reporting is temporarily unavailable, contact a maintainer privately and wait for a secure upload path before sharing exploit details or captured device data.

Supported versions

Dave is currently v0alpha1 and has no released stable version. Security fixes are applied to the latest main branch. The physical transport intentionally supports only adapter-registered read queries; arbitrary messages and hardware writes are out of scope until explicit authorization and recovery mechanisms exist.

There aren't any published security advisories