Do not disclose immediately exploitable vulnerabilities, credentials, private data, or real user data in public Issues or Discussions.
Email HmineCommons@gmail.com with the subject HMINE Security Report.
Include:
- the affected repository, version, and component;
- reproduction steps and a minimal proof;
- potentially affected data, authority, funds, or devices;
- known mitigations and whether a third-party vendor has been notified;
- your attribution preference and a safe way to contact you.
Highest priority includes arbitrary code execution, sandbox escape, supply-chain takeover, credential or private-memory disclosure, Agent permission bypass, unauthorized spending or migration, and undetectable alteration of contribution, settlement, or governance records.
The project will acknowledge receipt, assess impact, contain the issue, preserve evidence, prepare a fix, notify affected parties when appropriate, and conduct a retrospective. No response-time commitment is published for this early-stage project; do not assume that silence means a report is resolved.