Skip to content

Security: Musyg/stvault-audit

Security

SECURITY.md

Security Policy

Scope

StVault is an intentionally vulnerable demonstration contract. The findings documented in REPORT.md and exercised by test/StVault.poc.t.sol are expected behavior on the master branch and are not eligible for a bounty.

This repository is not production software, has no deployment, and holds no user funds. Do not deploy either branch.

Reporting an undisclosed issue

If you identify a distinct issue that is not already documented, use GitHub's private vulnerability-reporting channel when it is available. Otherwise, open a minimal issue that does not include weaponized details and ask for a private contact route.

Please include the affected commit, the relevant code path, impact and preconditions, and a reproducible test when possible.

There aren't any published security advisories