Skip to content

Security: HarshSingh21/EventMesh

Security

SECURITY.md

Security Policy

Supported versions

EventMesh is pre-1.0. Only main receives security fixes.

Version Supported
main ✅
Tagged releases ❌ (none yet)

Reporting a vulnerability

Do not open a public GitHub issue for security bugs.

Email the maintainer at security@eventmesh.invalid (replace with your real address) with:

  • A description of the vulnerability
  • Reproduction steps or PoC
  • Affected commit / version
  • Your assessment of impact

We aim to:

  • Acknowledge within 2 business days
  • Issue a fix or mitigation within 14 days for high-severity issues
  • Credit you in the release notes (unless you prefer anonymity)

Threat model (current state)

EventMesh today is a single-tenant local prototype. The threat model is small but worth stating explicitly:

Asset Threat Mitigation today Future work
Webhook endpoint Forged events None (loopback only) HMAC signature header
Database Direct compromise Default Postgres password — local dev only Secrets via env, never in image
LLM output Prompt injection via payload format: "json" + closed-set severity coercion Output validator + redaction layer
Process memory Oversize payload MaxBytesReader (1 MB cap), DisallowUnknownFields —

Out of scope (for now)

  • DoS against a publicly exposed webhook (we assume reverse-proxy rate limiting)
  • Side-channel attacks on the local Ollama model
  • Supply-chain attacks on transitive Go dependencies (covered by go mod verify)

Hardening checklist before production deploy

  • Change default Postgres credentials, manage via secret store
  • Place EventMesh behind a TLS-terminating reverse proxy
  • Enable HMAC signature verification on /webhook/events
  • Add per-tenant rate limiting
  • Enable Postgres row-level security on events.tenant_id
  • Configure structured-log shipping (no payload bodies in logs)
  • Restrict Ollama URL to a private network

There aren't any published security advisories