Skip to content

Security: DataUnion-app/Crab

SECURITY.md

Security policy

Supported version

Security fixes target the current main branch. Historical deployments and forks must be assessed by their operators.

Reporting

Please use GitHub's private vulnerability reporting form under the repository's Security tab. Do not open a public issue for a suspected vulnerability or include participant data, credentials, wallet private keys, access tokens, or live service details in a report.

Include the affected commit, the trust boundary involved, reproduction steps using generated data, and the expected impact. Maintainers will acknowledge the report, validate it, and coordinate a fix and disclosure when appropriate.

Deployment responsibility

The example configuration is not a production secret store. Operators must provide unique credentials, immutable image references, private database networking, backups, monitoring, and jurisdiction-appropriate privacy controls. Keep every optional real-data and reward capability disabled until its policy, consent, and operational gates have been reviewed.

There aren't any published security advisories