| Version | Supported |
|---|---|
| 1.0.x | ✅ |
If you discover a security vulnerability in OmniCurve, please report it responsibly:
- Do not create a public issue - Security vulnerabilities should be reported privately
- Email the maintainers at security@omnicurve.dev (or create a private GitHub security advisory)
- Include details:
- Description of the vulnerability
- Steps to reproduce
- Potential impact
- Suggested fix (if any)
- Acknowledgment: Within 48 hours
- Initial Assessment: Within 1 week
- Fix Development: Depends on severity (typically 2-4 weeks)
- Public Disclosure: After fix is released
- Always test on devnet/localnet before mainnet deployment
- Audit smart contracts before production use
- Use hardware wallets for mainnet transactions
- Verify contract addresses before interacting
- Never commit private keys or secrets
- Use environment variables for sensitive configuration
- Run security audits on dependencies
- Follow secure coding practices
- OmniCurve interacts with Meteora's DBC and DAMM v2 programs
- These programs have been audited but carry inherent smart contract risk
- Always verify program IDs before deployment
- Token launches involve financial risk
- Curve configurations can lead to unexpected price behavior
- Test thoroughly with various market conditions
- CLI tool requires wallet keypair access
- Use read-only wallets for monitoring
- Secure your RPC endpoints
We follow responsible disclosure practices:
- Vulnerability reported privately
- Fix developed and tested
- Patch released
- Public advisory published after users have time to upgrade
For security concerns, contact: security@omnicurve.dev