Skip to content

docs: establish vulnerability disclosure policy #136

Merged
ayomideadeniran merged 1 commit intoSoroLabs:mainfrom
Kanasjnr:docs/vulnerability-disclosure-policy
Mar 29, 2026
Merged

docs: establish vulnerability disclosure policy #136
ayomideadeniran merged 1 commit intoSoroLabs:mainfrom
Kanasjnr:docs/vulnerability-disclosure-policy

Conversation

@Kanasjnr
Copy link
Copy Markdown
Contributor

This PR establishes a formal Vulnerability Disclosure Policy (VDP) for the SoroTask platform by adding a SECURITY.md file to the root directory. This provides security researchers with a clear, safe, and professional channel to report identified vulnerabilities.

Related Issue

Closes #105

Type of Change

  • Feature
  • Bug fix
  • Refactor
  • Documentation

Changes Made

  • Added SECURITY.md: Created a comprehensive security policy.
  • Defined Policy Scope: Categorized scope into Primary (Smart Contracts & Protocol Logic) and Secondary (Keeper Service & Frontend Dashboard) to prioritize on-chain security.
  • Reporting Instructions: Added instructions to report via [email protected] (placeholder) with a structured format (Description, PoC, Impact).
  • Service Level Commitments: Outlined a 48-hour acknowledgment window and clear resolution timelines.
  • Safe Harbor: Included a safe harbor clause to protect researchers acting in good faith.

Validation

  • Manual verification completed (Verified file presence and content accuracy).
  • Formatting and Linting (Fixed MD022, MD032, and MD034 markdown lints).

Screenshots (if UI changes)

N/A (Documentation only)

Checklist

  • Scope is focused and avoids unrelated changes
  • Commit messages are clear
  • Documentation updated when needed
  • ETA was provided when requesting assignment for the linked issue

@drips-wave
Copy link
Copy Markdown

drips-wave bot commented Mar 29, 2026

@Kanasjnr Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits.

You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀

Learn more about application limits

@Kanasjnr
Copy link
Copy Markdown
Contributor Author

@ayomideadeniran ready for review

@ayomideadeniran
Copy link
Copy Markdown
Contributor

Pr under review.

@ayomideadeniran ayomideadeniran merged commit 305488e into SoroLabs:main Mar 29, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Security] Create a Comprehensive Vulnerability Disclosure Policy

2 participants