If you believe you have found a security vulnerability in StreamGive, please report it privately and responsibly.
Do not open a public GitHub issue for security reports. Please email us at:
Include the following information in your report:
- A clear description of the vulnerability
- The affected contract, module, or component
- Steps to reproduce the issue or a proof of concept
- The potential impact and severity
- Any suggested remediation or mitigation
We ask that you give us a reasonable amount of time to investigate and remediate the issue before disclosing it publicly.
We will do our best to acknowledge receipt of your report within 5 business days. We may ask for additional details to validate the issue and confirm the affected scope.
We appreciate responsible disclosure and will work with researchers to resolve confirmed vulnerabilities in a timely manner.
The project currently supports the latest commit on the main branch and the latest published release. Security fixes are prioritized for the current supported branch and release train.
Please do not disclose the vulnerability publicly until we have had a chance to assess and remediate it. If a fix is not available promptly, we may coordinate a reasonable disclosure timeline.
If you are reporting a vulnerability in a dependency or third-party library affecting this project, please include the dependency details and any reproduction steps.
This policy covers vulnerabilities in the StreamGive smart contracts, deployment tooling, and related repository code maintained in this project.
We do not accept reports for general bugs that do not create a security impact, or for issues already known to the project and publicly documented.