We take security vulnerabilities seriously. If you discover a security issue, please report it responsibly.
Please report security vulnerabilities by opening a GitHub Security Advisory:
- Go to the Security tab of this repository
- Click Report a vulnerability
- Provide details about the vulnerability
- Description of the vulnerability
- Steps to reproduce
- Potential impact
- Any suggested fixes (if applicable)
We aim to acknowledge receipt of your report within 48 hours and will keep you informed of our progress.
This policy covers:
- The smart contracts in
/contracts - The frontend application code
- Dependencies and their configurations
Please do not disclose the vulnerability publicly until we have had a chance to address it.