Only the main branch is actively supported with security updates. Older tags or branches may not receive fixes.
If you discover a security vulnerability in CarIn (smart contracts, frontend, or tooling), please report it privately rather than opening a public issue.
Preferred channel: open a private report via GitHub Security Advisories:
https://github.com/Uchechukwu-Ekezie/CarIn/security/advisories/new
You can also contact the maintainer directly: @Uchechukwu-Ekezie.
We will acknowledge your report within 48 hours and work with you to investigate and resolve the issue. Please give us a reasonable window to ship a fix before any public disclosure. We will keep you updated on remediation progress and credit you in the release notes if you wish.
In-scope:
- Clarity contracts under
smartcontracts/ - Solidity contracts under
smartcontracts-evm/andcontributions/ - Frontend application under
frontend/
Out of scope:
- Vulnerabilities in third-party dependencies that have already been disclosed upstream
- Findings that require physical access to a user device
- Social engineering attacks against maintainers or users