Skip to content

Security: MetroLogic/fluxapay_contract

Security

.github/SECURITY.md

Security Policy

Supported Versions

FluxaPay is in active pre-mainnet development. All contract code on the main branch is considered the current supported version. There are no legacy versions in production at this time.

Version / Branch Supported
main (latest) ✅ Yes
Older tags / branches ❌ No — please test against main

Reporting a Vulnerability

Please do not open a public GitHub issue for security vulnerabilities.

Use one of these private reporting channels:

Include in your report:

  • Affected contract(s) and function(s)
  • Steps to reproduce / proof-of-concept
  • Your severity assessment (Critical / High / Medium / Low)
  • Any suggested fix

Response Timeline

Stage SLA
Acknowledgment 24 hours
Triage & severity classification 72 hours
Fix commitment (Critical / High) 7 days
Fix commitment (Medium / Low) 30 days
Public disclosure ≤ 30 days after patch

Full Policy

For the complete disclosure policy, bug bounty details, CVE process, in-scope / out-of-scope contracts, and audit status, see SECURITY.md in the repository root.

There aren't any published security advisories