Skip to content

Security: lovyou-ai/eventgraph

Security

SECURITY.md

Security Policy

Reporting Vulnerabilities

If you discover a security vulnerability in EventGraph, please report it responsibly.

Email: security@lovyou.ai

Do NOT open a public GitHub issue for security vulnerabilities.

What Qualifies

  • Hash chain integrity bypasses
  • Signature verification bypasses
  • Authentication or authorisation flaws
  • Event injection or tampering vectors
  • Cross-graph reference forgery
  • Trust score manipulation
  • Information disclosure through the protocol

Response

We will acknowledge receipt within 48 hours and provide an initial assessment within 7 days. We will work with you to understand and address the issue before any public disclosure.

Scope

This policy covers the EventGraph packages and protocol. It does not cover third-party implementations or products built on EventGraph, though we will help coordinate disclosure where possible.

Hash Chain Integrity

The hash chain is the foundation of EventGraph's security model. Any contribution that weakens hash chain integrity — even accidentally — is a critical issue. If you notice a potential integrity weakness in a PR or in existing code, please flag it immediately.

There aren't any published security advisories