From 152b0978257fc11285f1642f081ff7e3dc10cf1a Mon Sep 17 00:00:00 2001 From: redshift <213178690+1ftredsh@users.noreply.github.com> Date: Sun, 16 Aug 2026 19:47:56 +0100 Subject: [PATCH] Add SECURITY.md with vulnerability reporting policy --- SECURITY.md | 23 +++++++++++++++++++++++ 1 file changed, 23 insertions(+) create mode 100644 SECURITY.md diff --git a/SECURITY.md b/SECURITY.md new file mode 100644 index 00000000..ad9097bd --- /dev/null +++ b/SECURITY.md @@ -0,0 +1,23 @@ +## SECURITY.md +# Security Policy + +## Reporting a Vulnerability + +Please report suspected security vulnerabilities privately to **team@routstr.com**. + +Do not open a public GitHub issue or disclose the vulnerability publicly until we have had a +reasonable opportunity to investigate and coordinate a fix. + +Please include, where possible: + +- The affected Routstr package and version or commit +- A description of the vulnerability and its potential impact +- Steps to reproduce or a proof of concept + +Do not include real Cashu tokens, seed phrases, private keys, or other secrets. + +We will acknowledge your report and coordinate remediation and disclosure with you. + +## Supported Versions + +Security fixes are provided for the latest released version. \ No newline at end of file