Skip to content

Security: Drcryptodee/argent

Security

SECURITY.md

Security Policy

Supported Versions

Argent is experimental and has not reached its first stable release. Security fixes are provided for the latest revision of the master branch only. Older revisions and generated artifacts may not receive security updates.

Reporting a Vulnerability

Before Argent's first stable release, security findings may be reported through the public issue tracker. Public reports help the compiler and its security model develop openly.

Use a private GitHub vulnerability report instead if the finding could put deployed contracts, funds, or users at risk, contains sensitive exploit details, or may require coordinated disclosure. If unsure, report it privately:

  1. Open the repository's Security advisories page.
  2. Click Report a vulnerability.
  3. Complete and submit the private vulnerability report.

After Argent's first stable release, report suspected security vulnerabilities privately. Do not disclose or discuss them in public channels before they have been investigated and a fix has been coordinated.

Please include as much of the following information as possible:

  • A description of the vulnerability and its potential impact.
  • The affected revision, component, and configuration.
  • Steps or a minimal example that reproduces the issue.
  • Any suggested mitigation or fix.
  • Whether the vulnerability has been disclosed elsewhere.

The maintainers will acknowledge the report as soon as practical, investigate it, and coordinate remediation and disclosure with the reporter. For private reports, please keep the report and related details private until the maintainers confirm that disclosure is safe.

For ordinary bugs, feature requests, and usage questions that do not have security implications, use the repository's public issue tracker instead.

There aren't any published security advisories