mirror of
https://github.com/Routstr/routstr-core.git
synced 2026-10-05 12:28:22 +00:00
Merge pull request #666 from Routstr/add-security-policy
Add SECURITY.md with vulnerability reporting policy
This commit is contained in:
+23
@@ -0,0 +1,23 @@
|
|||||||
|
## SECURITY.md
|
||||||
|
# Security Policy
|
||||||
|
|
||||||
|
## Reporting a Vulnerability
|
||||||
|
|
||||||
|
Please report suspected security vulnerabilities privately to **team@routstr.com**.
|
||||||
|
|
||||||
|
Do not open a public GitHub issue or disclose the vulnerability publicly until we have had a
|
||||||
|
reasonable opportunity to investigate and coordinate a fix.
|
||||||
|
|
||||||
|
Please include, where possible:
|
||||||
|
|
||||||
|
- The affected Routstr package and version or commit
|
||||||
|
- A description of the vulnerability and its potential impact
|
||||||
|
- Steps to reproduce or a proof of concept
|
||||||
|
|
||||||
|
Do not include real Cashu tokens, seed phrases, private keys, or other secrets.
|
||||||
|
|
||||||
|
We will acknowledge your report and coordinate remediation and disclosure with you.
|
||||||
|
|
||||||
|
## Supported Versions
|
||||||
|
|
||||||
|
Security fixes are provided for the latest released version.
|
||||||
Reference in New Issue
Block a user