Skip to content

Security: cyo12/sip-protocol

Security

SECURITY.md

Security Policy

Supported Versions

Version Supported
0.6.x
< 0.6

Reporting a Vulnerability

Please do NOT report security vulnerabilities through public GitHub issues.

Instead, please report them via email to: security@sip-protocol.org

Include:

  • Description of the vulnerability
  • Steps to reproduce
  • Potential impact
  • Any suggested fixes (optional)

What to Expect

  1. Acknowledgment: Within 48 hours
  2. Initial Assessment: Within 1 week
  3. Resolution Timeline: Depends on severity
    • Critical: 24-48 hours
    • High: 1 week
    • Medium: 2 weeks
    • Low: Next release

Disclosure Policy

  • We follow a 90-day disclosure timeline
  • We will coordinate disclosure with you
  • Credit will be given unless you prefer anonymity

Security Best Practices

For users of SIP Protocol:

  • Use hardware wallets for significant funds
  • Never share private keys or seed phrases
  • Verify URLs before connecting wallets
  • Keep software updated

Scope

In scope:

  • @sip-protocol/sdk
  • @sip-protocol/react
  • @sip-protocol/cli
  • @sip-protocol/api
  • @sip-protocol/types
  • sip-website

Out of scope:

  • Third-party dependencies (report to maintainers)
  • Social engineering attacks
  • Denial of service attacks

Bug Bounty

Coming soon. Details will be announced at https://sip-protocol.org/security

There aren’t any published security advisories