Security fixes are applied to the latest release on the main branch of BetterDevOrg/protocol.
Do not open a public GitHub issue for security vulnerabilities.
Please report security issues privately to the maintainers:
Include:
- Description of the issue
- Steps to reproduce
- Potential impact
- Suggested fix (if any)
We will acknowledge receipt and work on a fix as promptly as possible.
Reports related to the BetterDev application, API routes, authentication, and smart contracts deployed by the project are in scope.
General dependency vulnerabilities should be reported via the normal issue tracker unless they expose an active production risk.
Never commit private keys, API tokens, session secrets, or .env.local to the repository.