Please do not report security vulnerabilities through public GitHub issues.
Please report any vulnerability or any bug that could potentially affect the security of users' funds by mail to:
In the subject type [SeedSigner] Security Report: <short description>
and in the body a long description describing the issue. We aim to respond
within one week and patch within 90 days.
To help triage the report quickly, please include as much of the following as you can:
- The SeedSigner version
- A description of the vulnerability and its impact
- Steps to reproduce, ideally with a proof of concept
This policy covers SeedSigner and related build repos (ie seedsigner-os).