Skip to content

Security: viccoder-oops/stellar-stream-dashboard

Security

SECURITY.md

Security Policy

Supported versions

Version Supported
1.x

Reporting a vulnerability

If you discover a security vulnerability, please do not open a public GitHub issue.

Instead, send a report by email to the maintainer at victorignatius2@gmail.com with the subject line [SECURITY] stellar-stream-dashboard.

Include:

  • A description of the vulnerability and its potential impact.
  • Steps to reproduce or a proof-of-concept.
  • Your recommended fix (if any).

You will receive an acknowledgement within 72 hours and a resolution plan within 7 days.

Scope

The following are in scope:

  • Client-side code that could expose wallet credentials or signing sessions.
  • API integration code that could allow address spoofing or balance manipulation.
  • XSS or CSP bypass in the Next.js frontend.

The following are out of scope:

  • Vulnerabilities in third-party dependencies (report those upstream).
  • Social engineering attacks.
  • Issues requiring physical access to the user's device.

Disclosure policy

We follow a responsible disclosure policy: please give us 30 days to release a fix before public disclosure.

There aren't any published security advisories