Skip to content

Security: w3-kit/contracts

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

If you discover a security vulnerability in any w3-kit repository, please report it responsibly.

Do NOT open a public issue.

Instead, use GitHub's private vulnerability reporting on the affected repository.

What to include

  • Description of the vulnerability
  • Steps to reproduce
  • Affected repository and version
  • Potential impact

Scope

This policy covers all repositories in the w3-kit organization:

  • cli
  • registry
  • config
  • ui
  • website
  • learn
  • contracts

Response timeline

  • Acknowledgment: within 48 hours
  • Initial assessment: within 1 week
  • Fix or mitigation: depends on severity, typically within 30 days

Smart contracts

For vulnerabilities in w3-kit/contracts, please note that these are educational templates, not production-deployed contracts. We still take security seriously and will address reported issues promptly.

Supported Versions

We support the latest published version of each package. Older versions do not receive security patches.

There aren’t any published security advisories