Skip to content

docs: complete SECURITY.md with scope, disclosure timeline, and bug bounty#173

Merged
Vera3289 merged 1 commit into
Vera3289:mainfrom
devSoniia:feat/security-policy-64
Apr 26, 2026
Merged

docs: complete SECURITY.md with scope, disclosure timeline, and bug bounty#173
Vera3289 merged 1 commit into
Vera3289:mainfrom
devSoniia:feat/security-policy-64

Conversation

@devSoniia
Copy link
Copy Markdown
Contributor

Completes SECURITY.md to satisfy all acceptance criteria for #64.

  • Scope — lists in-scope contracts and vulnerability classes
  • Out of scope — explicit list of what is not eligible for bounty
  • Disclosure timeline — table with milestones and target windows
  • Bug bounty — severity tiers (Critical/High/Medium/Low) with USDC reward amounts

Closes #64

…ounty

- Add in-scope / out-of-scope sections
- Add coordinated disclosure timeline table
- Add bug bounty programme with severity/reward tiers
- Retain existing audit table and security design notes
- Reference threat-model.md and remediation.md

Closes Vera3289#64
@drips-wave
Copy link
Copy Markdown

drips-wave Bot commented Apr 26, 2026

@devSoniia Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits.

You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀

Learn more about application limits

@Vera3289 Vera3289 merged commit 2341c20 into Vera3289:main Apr 26, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Add SECURITY.md with responsible disclosure process

2 participants