Skip to content

Security: FissionDotFun/fission

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

If you discover a security vulnerability in Fission Protocol, please report it responsibly.

Do not open a public issue. Instead, email the details to the maintainers or use GitHub's private vulnerability reporting feature.

What to include

  • Description of the vulnerability
  • Steps to reproduce
  • Potential impact
  • Suggested fix (if any)

Response timeline

  • Acknowledgment: Within 48 hours
  • Initial assessment: Within 5 business days
  • Resolution: Depends on severity, typically within 30 days

Scope

The following are in scope:

  • Backend API endpoints
  • Worker logic (fee claiming, position management, buybacks)
  • On-chain verification logic
  • Authentication and authorization
  • Data handling and storage

Out of scope

  • Frontend-only cosmetic issues
  • Third-party dependencies (report upstream)
  • Social engineering attacks

Supported Versions

Version Supported
main Yes

There aren't any published security advisories