Skip to content

security: add CVE response timeline and disclosure policy to SECURITY.md (#518) - #530

Open
joan-bisbal wants to merge 1 commit into
MetroLogic:mainfrom
joan-bisbal:security/update-disclosure-policy
Open

security: add CVE response timeline and disclosure policy to SECURITY.md (#518)#530
joan-bisbal wants to merge 1 commit into
MetroLogic:mainfrom
joan-bisbal:security/update-disclosure-policy

Conversation

@joan-bisbal

Copy link
Copy Markdown

Security Disclosure Policy and CVE Response Process (#518)

  • Added 24h triage, 7-day critical fix, and 30-day full disclosure SLA timeline to SECURITY.md.
  • Specified in-scope Soroban smart contracts (PaymentProcessor, RefundManager, FXOracle, MerchantRegistry, PaymentLinkManager) and out-of-scope items.
  • Added contact security@fluxapay.com and references to �udits/SCOPE.md & �udits/external-audit-status.json.
  • Added .github/SECURITY.md for GitHub Security Advisory integration.

Payout Wallet (EVM): 0x20d3ea74f5534c760fb94753cfa3f4b7fce4d17f

Closes #518

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

security: add SECURITY.md disclosure timeline and CVE response process

1 participant