We release patches for security vulnerabilities. Which versions are eligible for receiving such patches depends on the CVSS v3.0 Rating:
| Version | Supported |
|---|---|
| 0.x | ✅ |
The Engram team takes security bugs seriously. We appreciate your efforts to responsibly disclose your findings, and will make every effort to acknowledge your contributions.
To report a security vulnerability, please use one of the following methods:
Report security vulnerabilities through GitHub's Security Advisory feature:
- Go to https://github.com/reallyartificial/engram/security/advisories
- Click "New draft security advisory"
- Fill in the details of your finding
Send an email to harsh.joshi.pth@gmail.com with:
- Type of issue (e.g., memory leak, data exposure, injection, etc.)
- Full paths of source file(s) related to the manifestation of the issue
- The location of the affected source code (tag/branch/commit or direct URL)
- Any special configuration required to reproduce the issue
- Step-by-step instructions to reproduce the issue
- Proof-of-concept or exploit code (if possible)
- Impact of the issue, including how an attacker might exploit it
- Response Time: You should receive a response within 48 hours.
- Acknowledgment: If the issue is confirmed, we will acknowledge it and work on a fix.
- Updates: We will keep you informed about the progress.
- Disclosure: We will coordinate with you on the disclosure timeline.
- The security report is received and assigned to a primary handler
- The problem is confirmed and a list of affected versions is determined
- Code is audited to find any similar problems
- Fixes are prepared for all supported releases
- An advisory is published
When using Engram in your projects:
-
Keep Dependencies Updated
npm update engram npm audit fix
-
Data Protection
- Never store sensitive credentials in memory stores
- Use encryption for sensitive data at rest
- Implement proper access controls
-
Environment Variables
- Never hardcode sensitive information
- Use environment variables for sensitive data
- Keep
.envfiles out of version control
-
Memory Isolation
- Use separate memory namespaces for different contexts
- Implement proper data lifecycle management
- Clear sensitive data when no longer needed
Engram includes several security considerations:
- Data Isolation: Namespace-based memory separation
- Input Validation: All inputs are validated before storage
- No Eval: No dynamic code execution via eval()
We regularly update our dependencies to include the latest security patches. You can check the current dependencies status:
npm auditFor any security-related questions that don't require reporting a vulnerability, please open a discussion in our GitHub repository.
Thank you for helping keep Engram and its users safe!