Report privately through GitHub's private vulnerability reporting on this repository's Security tab. Do not open a public issue for a vulnerability.
Include what you did, what happened, and what you expected. A failing test or a transaction hash on a public network makes a report far easier to act on.
Fixes land on the latest released version. 1.0.0 is the current one.
This library receives and records payments. The findings that matter most are the ones that break one of its stated guarantees:
- A payment that reaches the receiving account but is never recorded, or is recorded with the wrong amount, currency, issuer, or sender.
- A payment attributed to the wrong buyer, or a destination tag issued to two buyers.
- The ledger cursor advancing past ledgers that were never searched, which would turn a visible gap into a permanent one.
- A crafted transaction that stops the monitor — metadata is written by whoever built the payment path, so input reaching the balance-change reader is not trusted.
- Running more than one monitor against the same receiving account. It is documented as unsupported.
- A receiving account that holds DEX offers or has
DefaultRippleenabled. The README states what the account must be, and payments arriving in a shape that contradicts it are reported throughAnomalyCountby design. - MPT payments not being recorded. That is a documented limitation, and such a payment raises
AnomalyCountrather than disappearing quietly. - Anything in
samples/. The sample is a demonstration, not a hardened deployment: it has no authentication, and its endpoints expose payment data to anyone who can reach them.