From 23be42974e66906e5a0fcc777fd642688490d00d Mon Sep 17 00:00:00 2001 From: Jack Date: Wed, 19 Aug 2026 11:02:28 +0200 Subject: [PATCH 1/2] docs: add security policy (SFT-7581) --- SECURITY.md | 31 +++++++++++++++++++++++++++++++ 1 file changed, 31 insertions(+) create mode 100644 SECURITY.md diff --git a/SECURITY.md b/SECURITY.md new file mode 100644 index 0000000..692ef14 --- /dev/null +++ b/SECURITY.md @@ -0,0 +1,31 @@ +# Security Policy + +## Reporting a vulnerability + +Please do not open a public issue or discussion for a suspected security vulnerability. + +Report vulnerabilities privately through Foundation's responsible disclosure form: + +https://foundation.xyz/responsible-disclosure/ + +For encrypted email, contact `security@foundation.xyz` using Foundation's security disclosure PGP key: + +https://foundation.xyz/pgp-email/ + +Include, when possible: + +- the affected repository, product, version, release, or commit; +- the vulnerability's security impact; +- clear reproduction steps or a minimal proof of concept; +- relevant logs, screenshots, or traces with secrets and personal data removed; +- any suggested mitigation or fix. + +Do not include seed phrases, private keys, wallet passwords, API tokens, or customer data. + +## Disclosure process + +Please allow Foundation reasonable time to investigate and remediate the issue before public disclosure. Foundation's current scope, eligibility, disclosure requirements, and bounty terms are defined by the responsible disclosure policy linked above. + +## Supported versions + +Supported versions vary by project. Include the affected version or commit in your report. Foundation will confirm whether that version is currently supported and whether remediation will be applied to other maintained releases. From 41348edb743c168ef8574599f827ca4f0f61451c Mon Sep 17 00:00:00 2001 From: Jack Date: Wed, 19 Aug 2026 12:26:08 +0200 Subject: [PATCH 2/2] =?UTF-8?q?=EF=BB=BFdocs:=20add=20security=20policy=20?= =?UTF-8?q?license=20metadata=20(SFT-7581)?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- SECURITY.md | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/SECURITY.md b/SECURITY.md index 692ef14..15fc3f6 100644 --- a/SECURITY.md +++ b/SECURITY.md @@ -1,3 +1,9 @@ + + # Security Policy ## Reporting a vulnerability