Security fixes are applied to the actively developed version of the project.
Please report suspected vulnerabilities privately rather than opening a public issue.
Include:
- affected component
- reproduction steps
- potential impact
- suggested mitigation, if known
Never include secrets, private keys, API keys or credentials in vulnerability reports.
- least privilege
- environment-based secret management
- explicit blockchain write authorization
- centralized error handling
- automated testing
- code quality validation
This project is not an audited security product. Production deployments require an appropriate security review.