Skip to content

Security: digitaldesignerjazz/nexus

Security

SECURITY.md

Security Policy

Supported Versions

Version Supported
main ✅
0.1.x ✅
< 0.1 ❌

The main branch and the current 0.1 series receive security attention. Older experimental branches and tags are not actively maintained for security fixes.

Reporting a Vulnerability

We take the security of the Nexus ecosystem seriously — mesh, blockchain bridges, agent orchestration, and the surrounding infrastructure.

Please do not open public GitHub issues for security vulnerabilities.

Instead, report privately:

  • Prefer: GitHub Security Advisories ("Report a vulnerability" button on the repository Security tab)
  • Or contact the maintainer directly via the email associated with the repository owner account

What to include

  • Description of the vulnerability and its potential impact
  • Steps to reproduce (or proof-of-concept if available)
  • Affected components (Python reference layer, Rust orchestration core, mesh configs, CI, etc.)
  • Suggested remediation if you have one

Response expectations

  • Acknowledgement within 72 hours (usually faster)
  • Initial assessment and severity classification within 7 days
  • We will keep you informed of progress
  • Coordinated disclosure is preferred; we will work with you on timing

Security Updates

  • Dependabot is configured for both version updates and security alerts
  • Security-related dependency updates receive priority attention
  • Critical vulnerabilities in the supported versions will be addressed as quickly as possible

Supply Chain Security

The Nexus treats its own build and dependency pipeline as part of the trusted surface:

  • Dependency Review runs on every pull request and fails on high or critical severity findings.
  • SBOM (Software Bill of Materials) is generated automatically on pushes to main (CycloneDX format) and retained as a workflow artifact.
  • CodeQL continuously analyzes both the Python reference layer and the Rust orchestration core.
  • Dependabot keeps GitHub Actions, Cargo, and (when present) Python dependencies under observation.

These controls reduce the risk of compromised dependencies or malicious workflow changes entering the lattice.

Scope Notes

This policy primarily covers the code and configuration in this repository. Related repositories in the broader digitaldesignerjazz / Esslinger ecosystem may have their own policies or inherit this one.

Thank you for helping keep the lattice resilient.

There aren't any published security advisories