Skip to content

Security: ARPAHLS/legacy-protocol

Security

SECURITY.md

Security

Reporting a vulnerability

If private vulnerability reporting is enabled for arpahls/legacy-protocol, use it for sensitive issues (loss of funds, policy bypass, unauthorized execution).

If it is not enabled, contact maintainers through the channel published on github.com/arpahls. Do not post full exploit chains in public issues before coordination.

Scope

As smart contracts and operational components are added to this repository, this file will list in-scope paths and out-of-scope items (for example third-party frontends not maintained here).

Acknowledgments

Security researchers who report valid issues may be credited in release notes or a hall of fame at maintainer discretion.

There aren't any published security advisories