FluxaPay is in active pre-mainnet development. All contract code on the main branch is considered the current supported version. There are no legacy versions in production at this time.
| Version / Branch | Supported |
|---|---|
main (latest) |
✅ Yes |
| Older tags / branches | ❌ No — please test against main |
Please do not open a public GitHub issue for security vulnerabilities.
Use one of these private reporting channels:
- Email: security@fluxapay.com
- GitHub Private Security Advisory: Click "Report a vulnerability" on the Security tab of this repository.
Include in your report:
- Affected contract(s) and function(s)
- Steps to reproduce / proof-of-concept
- Your severity assessment (Critical / High / Medium / Low)
- Any suggested fix
| Stage | SLA |
|---|---|
| Acknowledgment | 24 hours |
| Triage & severity classification | 72 hours |
| Fix commitment (Critical / High) | 7 days |
| Fix commitment (Medium / Low) | 30 days |
| Public disclosure | ≤ 30 days after patch |
For the complete disclosure policy, bug bounty details, CVE process, in-scope / out-of-scope contracts, and audit status, see SECURITY.md in the repository root.