Skip to content

docs: add SECURITY.md + drop unaudited disclaimer#465

Open
adamkrellenstein wants to merge 1 commit into
mainfrom
security/policy-and-disclaimer
Open

docs: add SECURITY.md + drop unaudited disclaimer#465
adamkrellenstein wants to merge 1 commit into
mainfrom
security/policy-and-disclaimer

Conversation

@adamkrellenstein

@adamkrellenstein adamkrellenstein commented Jun 3, 2026

Copy link
Copy Markdown
Contributor

Adds a SECURITY.md (private vulnerability reporting via GitHub's Security tab, scope, and pointers to the spec-level threat models) and rewords the README's experimental warning to drop the "unaudited" framing. Docs only.


Note

Low Risk
Documentation-only changes with no runtime, API, or security logic modifications.

Overview
Adds a SECURITY.md that directs researchers to GitHub private vulnerability reporting, defines in-scope components (core/, native-contracts/, consensus/determinism), what to report elsewhere (Kontor-Crypto), and links to spec-level threat models plus a pre-mainnet status note.

The README warning is reworded from unaudited and experimental to experimental and pre-release, removing the explicit unaudited label while keeping a use-at-your-own-risk disclaimer.

Reviewed by Cursor Bugbot for commit 8e32ffd. Bugbot is set up for automated code reviews on this repo. Configure here.

- SECURITY.md: vulnerability-disclosure policy via GitHub private reporting,
  scope, and pointers to the spec-level threat models.
- README: reword the experimental warning to drop the "unaudited" framing.
@adamkrellenstein adamkrellenstein added docs Documentation / specs security Security-sensitive labels Jun 3, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

docs Documentation / specs security Security-sensitive

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant