Skip to content

Security: pulkit136/sera-sdk

Security

SECURITY.md

Security Policy

We take the security of our users and the Sera Protocol very seriously. If you discover a vulnerability, please report it following the guidelines below.


Supported Versions

Only the latest active major and minor releases of the SDK receive security patches. Please upgrade to the latest stable version if you encounter an issue.

Version Supported
>= 1.0.0 Active
< 1.0.0 Unsupported (Beta / Dev)

Reporting a Vulnerability

DO NOT file public GitHub issues for security vulnerabilities.

Instead, please send security reports directly to our core security team:

  • Email: pulkitlather.work@gmail.com
  • Response Time: We acknowledge receipt of security reports within 24 hours and aim to provide a fix or mitigation guide within 7 days.

Responsible Disclosure

To protect the users of the stablecoin FX CLOB settlement engine, we ask that you:

  • Provide detailed steps to reproduce the vulnerability.
  • Do not disclose the issue publicly until we have resolved it or provided a patch.
  • Do not attempt to exploit the vulnerability on active mainnet deployments.

There aren't any published security advisories