Skip to content

Security: W9MDM/SARMesh

Security

SECURITY.md

Security Policy

We take the security of our project seriously and appreciate your efforts to help us keep it safe.

Reporting a Vulnerability

If you believe you have found a security vulnerability, please do not report it via a public GitHub issue. Instead, please

If the issue is inherited from upstream Mesh-Client rather than SARMesh-specific, please also notify upstream at nv0n@coloradomesh.org so every fork gets the fix.

To help us investigate and triage the issue as quickly as possible, please include:

  • Type of issue (e.g., buffer overflow, SQL injection, cross-site scripting).
  • Full paths of source files related to the manifestation of the issue.
  • Step-by-step instructions to reproduce the vulnerability.
  • Proof-of-concept or exploit code (if possible).
  • Impact of the issue, including how an attacker might exploit it.

Response Timeline

We strive to respond to all reports within 48 hours. Once we confirm a vulnerability, we will work to address it and keep you updated on the expected timeline for a patch.

Supported Versions

We currently provide security updates only for the code in main and the latest release.

Disclosure Policy

We encourage responsible disclosure. Please do not make any security vulnerability public until we have had sufficient time to evaluate, patch, and deploy a fix.

There aren't any published security advisories