| Version | Supported |
|---|---|
main (latest) |
Yes |
| Latest tagged release | Yes |
| Older releases | Best effort |
Do not open a public GitHub issue for security vulnerabilities.
| Channel | Details |
|---|---|
| security@safrochain.com | |
| Subject | [safhandle-sdk] Brief description |
- Client-side address spoofing or cache poisoning
- Incorrect resolution before transaction signing
- Leaking phone numbers to third-party analytics
- Hardcoded private keys or contract addresses in examples
- Supply-chain issues in npm dependencies
| Stage | Target |
|---|---|
| Initial acknowledgment | 2 business days |
| Severity assessment | 5 business days |
| Fix or mitigation plan | 15 business days |
Good-faith security research is welcome when it follows responsible disclosure and does not harm users.
Monitored via Dependabot and CI audits once dependencies are added.