Skip to content

Security: StellarTickets/blockchain

Security

SECURITY.md

Security Policy

Reporting a vulnerability

If you find a security issue in the ticketing contract (an authorization bypass, an integer overflow path, a way to mint or transfer a ticket without the correct signer, etc.), please do not open a public issue.

Instead, contact the maintainers privately:

  • GitHub: @presidojay1 (via GitHub Security Advisories)
  • Security reporting: Use GitHub's private vulnerability reporting feature on this repository:
    1. Go to Security → Advisories → Report a vulnerability
    2. Describe the issue, severity, and affected versions
    3. The maintainers will receive your report confidentially

Please include:

  • A clear description of the vulnerability
  • Steps to reproduce (if applicable)
  • Affected contract version(s)
  • Your suggested fix (if any)

We aim to acknowledge security reports within 48 hours and provide an update within 7 days.

Scope

This contract has not had a third-party audit yet. Treat it as testnet-only until one has been completed.

Supported versions

Version Supported
0.1.x ✅ (testnet only)

Acknowledgments

We recognize the security research community's efforts in keeping this project secure. Significant vulnerability reports may be acknowledged here (with reporter consent) once patches are released.

There aren't any published security advisories