Skip to content
This repository has been archived by the owner on Nov 9, 2023. It is now read-only.

Security: dusk-network/plonk_gadgets

Security

.github/SECURITY.md

Reporting Security Vulnerabilities

Dusk values the security and integrity of our open-source software libraries and strives to provide a secure experience for our users and partners. As part of our commitment to security, we have established a Coordinated Vulnerability Disclosure (CVD) process to ensure that any potential vulnerabilities in our technology are responsibly and promptly addressed.

If you discover a potential vulnerability in any of our software libraries, please follow these guidelines below to report it using GitHub’s vulnerability reporting feature:

  1. Do not publicly disclose the vulnerability or exploit it.
  2. Navigate to the main page of the affected repository on GitHub.com.
  3. Click “Security” under the repository name. If it’s not visible, select the dropdown menu, and then click “Security”.
  4. Click “Advisories” in the left sidebar under “Reporting”.
  5. Select “Report a vulnerability” to open the advisory form. Fill in the advisory form, including details about the affected library, version, vulnerability description, and reproduction steps.
  6. Our team will acknowledge receipt of the report within three working days and provide an estimated timeline for resolution.
  7. We will collaborate with the reporter to thoroughly understand, investigate and develop a fix for the vulnerability.
  8. After developing and deploying the fix, we will notify the reporter and any affected parties, as applicable.
  9. Our team will publicly disclose the vulnerability and the steps taken to address it. The reporter and the associated organization will be thanked and acknowledged for their efforts and contribution.

By adhering to this process, we can work together to ensure the security and integrity of our open-source libraries, safeguarding the assets of our users and partners. We appreciate your efforts in helping us maintain the security of our technology.

There aren’t any published security advisories