| Version | Supported |
|---|---|
| 1.x | ✅ |
If you discover a security vulnerability, please do not open a public GitHub issue.
Instead, send a report by email to the maintainer at victorignatius2@gmail.com with the subject line [SECURITY] stellar-stream-dashboard.
Include:
- A description of the vulnerability and its potential impact.
- Steps to reproduce or a proof-of-concept.
- Your recommended fix (if any).
You will receive an acknowledgement within 72 hours and a resolution plan within 7 days.
The following are in scope:
- Client-side code that could expose wallet credentials or signing sessions.
- API integration code that could allow address spoofing or balance manipulation.
- XSS or CSP bypass in the Next.js frontend.
The following are out of scope:
- Vulnerabilities in third-party dependencies (report those upstream).
- Social engineering attacks.
- Issues requiring physical access to the user's device.
We follow a responsible disclosure policy: please give us 30 days to release a fix before public disclosure.