Skip to content

Latest commit

 

History

History
58 lines (40 loc) · 2.14 KB

File metadata and controls

58 lines (40 loc) · 2.14 KB

Security Policy

Supported Versions

We actively support and provide security updates for the following versions:

Version Supported
Latest
Previous major versions ✅ (for 6 months after new major release)

Reporting a Vulnerability

If you discover a security vulnerability, please do not report it publicly. Instead, please follow these steps:

  1. Email us directly at eng@mento.org with details about the vulnerability

  2. Include as much information as possible:

    • Description of the vulnerability
    • Steps to reproduce
    • Potential impact
    • Suggested fix (if any)
  3. We will acknowledge receipt of your report within 72 hours

  4. We will provide an initial assessment within 7 days

  5. We will keep you informed of our progress and resolution timeline

Security Best Practices

When reporting vulnerabilities, please:

  • Do not create a public GitHub issue
  • Do not discuss the vulnerability publicly until it has been resolved
  • Do provide detailed information to help us understand and reproduce the issue
  • Do allow us reasonable time to address the issue before public disclosure

Response Timeline

  • Initial Response: Within 72 hours
  • Status Update: Within 7 days
  • Fix Timeline: Depends on severity:
    • Critical: Immediate attention, fix within 24-48 hours
    • High: Fix within 7 days
    • Medium: Fix within 30 days
    • Low: Fix in next scheduled release

Recognition

We appreciate responsible disclosure and will acknowledge security researchers who help us improve the security of our project (with your permission).

Security Updates

Security updates will be released as soon as possible after a vulnerability is confirmed and fixed. We will:

  • Release patches for supported versions
  • Publish a security advisory on GitHub
  • Credit the reporter (if desired)

Thank you for helping keep Mento Protocol secure!