Skip to content

Latest commit

 

History

History
51 lines (33 loc) · 1.91 KB

File metadata and controls

51 lines (33 loc) · 1.91 KB

Security Policy

Supported Versions

Use this section to tell people about which versions of your project are currently being supported with security updates.

Version Supported
v1.0.x
< v1.0

Scope

This security policy applies to all smart contracts and related software within the ApexChainx-Contracts repository.

Dependency Updates

Dependency updates that may introduce security or compatibility impacts should use the Dependency Security Review issue template before opening a pull request.

This helps maintainers evaluate security, compatibility, licensing, and supply-chain risks before changes are merged.

Reporting a Vulnerability

We take the security of our smart contracts seriously. If you believe you have found a security vulnerability in our contracts, please report it to us as described below.

Please do not report security vulnerabilities through public GitHub issues.

Instead, please email your findings to [security@apexchainx.example.com].

Secure Reporting Method

You can encrypt your communication using our PGP key:

-----BEGIN PGP PUBLIC KEY BLOCK-----
...
-----END PGP PUBLIC KEY BLOCK-----

(Please contact us for the actual PGP key if needed, or use the email provided above securely.)

Response Timeline

  • We will acknowledge receipt of your vulnerability report within 48 hours.
  • We will provide a more detailed response to your report within 7 days, including whether we have reproduced the issue and an estimated timeline for remediation.
  • We aim to resolve critical issues within 14 days of confirmation.

Disclosure Policy

We ask that you do not disclose the vulnerability publicly until we have had a chance to address it. We will notify you when the issue has been patched and is safe to disclose. We appreciate your cooperation in keeping our ecosystem secure.