Please do not report security vulnerabilities through public GitHub issues, discussions, or pull requests.
To report a suspected security vulnerability, contact the Project Funding Ledger maintainers privately at:
Please include:
- A description of the vulnerability
- Steps to reproduce the issue
- The potential impact
- Any suggested remediation, if available
The maintainers will acknowledge the report and evaluate the issue as promptly as reasonably possible.
Please do not publicly disclose the vulnerability until the maintainers have had a reasonable opportunity to investigate and address it.
The Project Funding Ledger is currently under development and has not yet issued a production release.
Security updates will generally apply to the latest version of the main development branch until a formal release and version-support policy is established.