Skip to content

Latest commit

 

History

History
37 lines (26 loc) · 1.37 KB

File metadata and controls

37 lines (26 loc) · 1.37 KB

Security Policy

Reporting a vulnerability

If you discover a security issue in the Demos Network Oracle — whether in the code at this repository, in the live service at demos-oracle.com, or in the data it publishes — please report it privately before disclosing publicly.

Contact: cypherx22@protonmail.com

Please include:

  • A description of the issue
  • Steps to reproduce (if applicable)
  • The potential impact
  • Your contact information (optional)

Scope

In scope:

  • The Oracle service at demos-oracle.com and its API endpoints
  • The source code in this repository
  • Data integrity issues in /organism output or any other published endpoint
  • Authentication / authorization issues on admin endpoints

Out of scope:

  • The Demos blockchain itself (report to the Demos team)
  • SuperColony infrastructure (report to SuperColony)
  • Third-party services the Oracle observes (e.g., individual validator nodes)
  • Issues in deprecated endpoints that are no longer publicly reachable

What to expect

  • Acknowledgment of your report within a reasonable time frame
  • Coordinated disclosure if the issue warrants it
  • Credit in any public disclosure (if you want it)

No bug bounty

This is an independent, unfunded community service. There is no bug bounty program. Reports are appreciated and will be handled with care, but no monetary reward is offered.