Skip to content

Security: levyflux/tx-assertion-lab

SECURITY.md

Security policy

Project status

tx-assertion-lab is experimental protocol research software. It has not been audited and must not be treated as production transaction-security infrastructure.

Only the latest revision of the main branch is currently maintained. Draft EIP profiles are provisional and may change incompatibly.

Reporting a vulnerability

For a vulnerability that could put users, funds, private data, or downstream systems at risk, use GitHub's private vulnerability reporting for this repository. Do not open a public issue before coordinated disclosure.

For non-sensitive correctness bugs, reproducible conformance differences, and documentation problems, open a normal GitHub issue. A client difference is treated as unresolved until it is compared with an authoritative expectation; please include pinned versions, inputs, outputs, and a minimal reproduction.

Reports should include:

  • affected commit and environment;
  • impact and violated invariant;
  • minimal reproduction or proof of concept;
  • expected and observed behavior;
  • any known workaround.

Receipt of a report does not imply eligibility for a monetary reward. This project does not currently operate its own bug bounty program.

There aren't any published security advisories