Skip to content

Security: Celo-HaiTi/celoht-admin

Security

SECURITY.md

Security Policy

Reporting a vulnerability

Email security@celoht.com with a description and reproduction steps. Please don't open a public issue for undisclosed vulnerabilities.

We aim to acknowledge reports within 5 business days.

Scope

This repository handles governance, treasury, and program data for CeloHT. In-scope concerns include: RLS policy bypass, auth/session handling, XSS/CSRF in dashboard forms, and dependency vulnerabilities flagged by CodeQL/Dependabot.

Supported versions

Only the main branch receives security fixes.

There aren't any published security advisories