This project follows the OpenWallet Foundation security vulnerability disclosure policy.
Security fixes are applied to the main branch and published in the next
release. Older releases are not patched; consumers are expected to upgrade to
the latest release.
Please do not open a public GitHub issue for security problems.
Report vulnerabilities privately through GitHub Security Advisories:
See GitHub's guide on privately reporting a security vulnerability if you are unfamiliar with the process.
If you are unable to use GitHub Security Advisories, contact the maintainers on
the vcx Discord channel
and ask for a private channel to disclose the issue. Do not include details of
the vulnerability in a public message.
Include as much of the following as you can:
- The affected crate(s) and version or commit.
- A description of the issue and its impact.
- Steps to reproduce, including a proof of concept where possible.
- Any suggested mitigation.
- Acknowledgement of your report within 5 business days.
- An initial assessment, including whether we consider it a vulnerability, within 10 business days.
- Coordinated disclosure: we aim to publish a fix and a GitHub Security Advisory (with a CVE where applicable) within 90 days of the report. We will keep you informed of progress and agree a disclosure date with you.
- Credit in the published advisory, unless you ask to remain anonymous.
In scope: the crates and agents in this repository.
Out of scope: vulnerabilities in upstream dependencies (report those to the relevant project, and let us know so we can bump the dependency), and issues that require an already-compromised host or wallet.