Skip to content

Security: Beluba/omnicurve

Security

SECURITY.md

Security Policy

Supported Versions

Version Supported
1.0.x ✅

Reporting a Vulnerability

If you discover a security vulnerability in OmniCurve, please report it responsibly:

  1. Do not create a public issue - Security vulnerabilities should be reported privately
  2. Email the maintainers at security@omnicurve.dev (or create a private GitHub security advisory)
  3. Include details:
    • Description of the vulnerability
    • Steps to reproduce
    • Potential impact
    • Suggested fix (if any)

Response Timeline

  • Acknowledgment: Within 48 hours
  • Initial Assessment: Within 1 week
  • Fix Development: Depends on severity (typically 2-4 weeks)
  • Public Disclosure: After fix is released

Security Best Practices

For Users

  • Always test on devnet/localnet before mainnet deployment
  • Audit smart contracts before production use
  • Use hardware wallets for mainnet transactions
  • Verify contract addresses before interacting

For Contributors

  • Never commit private keys or secrets
  • Use environment variables for sensitive configuration
  • Run security audits on dependencies
  • Follow secure coding practices

Known Security Considerations

Smart Contract Risk

  • OmniCurve interacts with Meteora's DBC and DAMM v2 programs
  • These programs have been audited but carry inherent smart contract risk
  • Always verify program IDs before deployment

Economic Risk

  • Token launches involve financial risk
  • Curve configurations can lead to unexpected price behavior
  • Test thoroughly with various market conditions

Operational Security

  • CLI tool requires wallet keypair access
  • Use read-only wallets for monitoring
  • Secure your RPC endpoints

Disclosure Policy

We follow responsible disclosure practices:

  1. Vulnerability reported privately
  2. Fix developed and tested
  3. Patch released
  4. Public advisory published after users have time to upgrade

Contact

For security concerns, contact: security@omnicurve.dev

There aren't any published security advisories