Skip to content

Security: ozpool/devbounty-backend

Security

SECURITY.md

Security policy

Supported versions

The latest tagged release on main is supported.

Reporting a vulnerability

Email security@devbounty.example (placeholder — replace before go-live).

Do not open a public issue for security reports. Expect an initial response within 72 hours.

Scope

  • Smart contract logic (contracts/BountyEscrow.sol)
  • Backend API and indexer (this repo)
  • Frontend (devbounty-web)

Out of scope

  • Social engineering of contributors
  • DoS via paid Alchemy quota
  • Issues in deployment infrastructure (Vercel, Render, Atlas) — report to those vendors directly

There aren't any published security advisories