EventMesh is pre-1.0. Only main receives security fixes.
| Version | Supported |
|---|---|
main |
✅ |
| Tagged releases | ❌ (none yet) |
Do not open a public GitHub issue for security bugs.
Email the maintainer at security@eventmesh.invalid (replace with your real address) with:
- A description of the vulnerability
- Reproduction steps or PoC
- Affected commit / version
- Your assessment of impact
We aim to:
- Acknowledge within 2 business days
- Issue a fix or mitigation within 14 days for high-severity issues
- Credit you in the release notes (unless you prefer anonymity)
EventMesh today is a single-tenant local prototype. The threat model is small but worth stating explicitly:
| Asset | Threat | Mitigation today | Future work |
|---|---|---|---|
| Webhook endpoint | Forged events | None (loopback only) | HMAC signature header |
| Database | Direct compromise | Default Postgres password — local dev only | Secrets via env, never in image |
| LLM output | Prompt injection via payload | format: "json" + closed-set severity coercion |
Output validator + redaction layer |
| Process memory | Oversize payload | MaxBytesReader (1 MB cap), DisallowUnknownFields |
— |
- DoS against a publicly exposed webhook (we assume reverse-proxy rate limiting)
- Side-channel attacks on the local Ollama model
- Supply-chain attacks on transitive Go dependencies (covered by
go mod verify)
- Change default Postgres credentials, manage via secret store
- Place EventMesh behind a TLS-terminating reverse proxy
- Enable HMAC signature verification on
/webhook/events - Add per-tenant rate limiting
- Enable Postgres row-level security on
events.tenant_id - Configure structured-log shipping (no payload bodies in logs)
- Restrict Ollama URL to a private network