Skip to content

Security: dfinity/imcp2

Security

SECURITY.md

Security Policy

DFINITY takes the security of our software products seriously, which includes all source code repositories under the DFINITY GitHub organization.

Important

DFINITY Foundation has a Internet Computer (ICP) Bug Bounty program that rewards researchers for finding and reporting vulnerabilities in the Internet Computer. Please check the scope and eligibility criteria outlined in the policy to see if the vulnerability you found qualifies for a reward.

How to report a vulnerability

We appreciate your help in keeping our projects secure. If you believe you have found a security vulnerability in any of our repositories, please report it responsibly to us as described below:

  1. Do not disclose the vulnerability publicly. Public disclosure could be exploited by attackers before it can be fixed. In particular, please do not report it through public GitHub issues, pull requests, or discussions.
  2. Disclose the vulnerability through Hackenproof
    • Hackenproof facilitates disclosure and streamlines Bugbounty payouts.

We will respond to your report within 72 hours and work with you to fix the vulnerability as soon as possible.

To help us triage quickly, please include what you can of the following:

  • A description of the vulnerability and its potential impact.
  • Steps to reproduce, or a proof of concept.
  • The affected version, commit, or deployment.
  • Any suggested mitigation, if you have one.

Security Updates

We are committed to fixing security vulnerabilities in a timely manner. Once a security vulnerability is reported, we will:

  • Investigate the report and confirm the vulnerability.
  • Develop a fix for the vulnerability.
  • Release a new version of the project that includes the fix.
  • Announce the security fix in the project's release notes.

Supported versions

This project is under active development and has not yet reached a stable 1.0 release. Security fixes are applied to the latest revision on the main branch and reach the deployment on the next release-* tag.

Preferred Language

We prefer all communications to be in English.

Disclaimer

This security policy is subject to change at any time.

There aren't any published security advisories