Skip to content

Security: algorandfoundation/xgov-beta-web

Security

SECURITY.md

Security Policy

Supported Versions

Security fixes are provided for the latest release on the default branch. If you are running an older commit or a fork, please rebase/upgrade before reporting issues.

Reporting a Vulnerability

If you believe you have found a security vulnerability, please do not open a public GitHub issue.

Instead, report it privately by emailing:

What to Include

Please include:

  • A description of the issue and potential impact
  • Steps to reproduce (proof-of-concept if available)
  • Affected components (pages, API routes, packages)
  • Any relevant logs, screenshots, or stack traces
  • Your suggested fix or mitigation (optional)

Response Targets

We aim to:

  • Acknowledge receipt within 3 business days
  • Provide a status update within 10 business days

Timelines may vary depending on severity and complexity.

Coordinated Disclosure

We prefer coordinated vulnerability disclosure. Please allow reasonable time for investigation and remediation before public disclosure.

Vulnerability Rewards

This repository does not currently operate a public bug bounty. If that changes, it will be documented here.

There aren’t any published security advisories