Skip to content

Commit 3448a61

Browse files
authored
docs: create SECURITY.md
Add draft security policy
1 parent c43ecd6 commit 3448a61

File tree

1 file changed

+25
-0
lines changed

1 file changed

+25
-0
lines changed

SECURITY.md

+25
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,25 @@
1+
# Security Policy
2+
3+
The ICON Bridge is in early development and may contain security vulnerabilities.
4+
5+
## Security Audit
6+
7+
The ICON Bridge is currently being audited. We will make the audit report public after it is complete
8+
and all discovered vulnerabilities have been addressed.
9+
10+
## Bug Bounty
11+
12+
TBD after audit completes.
13+
14+
## Supported Versions
15+
16+
Please see the [releases page](https://github.com/icon-project/icon-bridge/releases) for the list of supported version.
17+
18+
## Reporting a Vulnerability
19+
20+
All security related issues should be reported via email to security@icon.foundation. We will attempt to respond within 2 business days to all reported issues.
21+
22+
## Fixing a Vulnerability
23+
24+
Development for security issues should be done in a private fork and publicly commited ONLY after the fix is already on mainnet.
25+
[See Github's steps on how to develop in a private fork](https://docs.github.com/en/code-security/repository-security-advisories/collaborating-in-a-temporary-private-fork-to-resolve-a-repository-security-vulnerability).

0 commit comments

Comments
 (0)