Join the contributor Telegram: https://t.me/+DOylgFv1jyJlNzM0
Why this matters
There is no SECURITY.md, so researchers reporting a vulnerability have no canonical address, no disclosure window, and no scope statement. GitHub flags this as a security policy gap, and Stellar/Soroban projects without one face higher friction with bounty programs. A short, honest SECURITY.md is mostly boilerplate but signals seriousness.
Acceptance criteria
Files to touch
SECURITY.md (new)
README.md
Out of scope
- Running a paid bounty programme.
- Adding a GPG key right now (mention the option only).
Join the contributor Telegram: https://t.me/+DOylgFv1jyJlNzM0
Why this matters
There is no
SECURITY.md, so researchers reporting a vulnerability have no canonical address, no disclosure window, and no scope statement. GitHub flags this as a security policy gap, and Stellar/Soroban projects without one face higher friction with bounty programs. A short, honest SECURITY.md is mostly boilerplate but signals seriousness.Acceptance criteria
SECURITY.mdat the repo root with:main+ last tag).README.md"Security" section.Files to touch
SECURITY.md(new)README.mdOut of scope