Report vulnerabilities privately:
- Preferred: private GitHub Security Advisory —
https://github.com/alrimarleskovar/forewarn/security/advisories/new - Alternative: e-mail
alrimar6@gmail.com
Do not open a public issue for security flaws. We will respond within 7 days.
This project is read-only analytics:
- No custody of funds. No smart contracts of our own. No transaction execution.
- There is no product code in production at this stage (pre-build validation).
The actual risk surface is:
- Dependencies (npm in
packages/ingestion/, pip/uv inquant/, GitHub Actions) — monitored by Dependabot and CodeQL. - Secret leakage — RPC/Dune keys and
.envfiles (never committed; see.gitignore; secret scanning + push protection enabled in the repo settings). - Supply chain — compromised packages, unpinned actions.
A real audit (of the risk model and any product contract/code) comes after the validation verdict — there is no product code to audit at this stage. Day 1 covers posture + automated scanning (CodeQL, Dependabot, secret scanning), not a code audit.
| Version | Supported |
|---|---|
main |
✅ |