If you discover a security vulnerability in Fission Protocol, please report it responsibly.
Do not open a public issue. Instead, email the details to the maintainers or use GitHub's private vulnerability reporting feature.
- Description of the vulnerability
- Steps to reproduce
- Potential impact
- Suggested fix (if any)
- Acknowledgment: Within 48 hours
- Initial assessment: Within 5 business days
- Resolution: Depends on severity, typically within 30 days
The following are in scope:
- Backend API endpoints
- Worker logic (fee claiming, position management, buybacks)
- On-chain verification logic
- Authentication and authorization
- Data handling and storage
- Frontend-only cosmetic issues
- Third-party dependencies (report upstream)
- Social engineering attacks
| Version | Supported |
|---|---|
| main | Yes |