HyperFaucet security fixes target the latest published release and the current default branch. Older releases may not receive backports.
| Version | Supported |
|---|---|
| Latest release | Yes |
| Older releases | No |
Send confidential reports to murakamikaze@validao.xyz. Include the affected version or commit,
impact, reproduction steps, and any suggested fix. Do not send private keys, production secrets,
or more live data than the reproduction requires.
Do not open a public issue for an unpatched vulnerability. Give ValiDAO a reasonable opportunity to confirm and fix the problem before disclosure. We will acknowledge the report, reproduce it, and coordinate a release and disclosure timeline with you.
Use GitHub Issues for ordinary bugs that do not expose users, funds, credentials, or infrastructure.
This policy covers HyperFaucet code and ValiDAO-operated HyperFaucet services. Report inherited PoWFaucet defects here when they affect HyperFaucet; we will coordinate upstream when appropriate.