From 2e82f28a51113f4ac50ac105af96e54109beab27 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?S=C3=A9rgio?= Date: Fri, 25 Sep 2026 03:17:55 -0300 Subject: [PATCH] feat(bounty): populate launch fields and security configurations --- BOUNTY.md | 24 +++++++++++++++ SECURITY.md | 84 +++++++--------------------------------------------- security.txt | 7 +++++ 3 files changed, 41 insertions(+), 74 deletions(-) create mode 100644 BOUNTY.md create mode 100644 security.txt diff --git a/BOUNTY.md b/BOUNTY.md new file mode 100644 index 0000000..f72436b --- /dev/null +++ b/BOUNTY.md @@ -0,0 +1,24 @@ +# Citrate Network Bounty Program + +## Rewards +| Severity | Reward (USD) | +|-----------|--------------| +| Critical | 50,000 | +| High | 10,000 | +| Medium | 2,500 | +| Low | 500 | + +## Launch Details +- **Launch Date**: 2024-06-15 +- **Payout Method**: Multi-signature wallet (2/3) +- **Currency**: USDC +- **KYC Requirement**: Mandatory for payouts > $1,000 +- **Eligibility**: Open to all except Citrate employees/contractors + +## Payout Process +1. Submit vulnerability report via [security@citrate.ai](mailto:security@citrate.ai) +2. Undergo KYC verification if applicable +3. Receive USDC payout to verified address + +## Encryption +**PGP Key**: [security@citrate.ai](https://citrate.ai/.well-known/security.txt) diff --git a/SECURITY.md b/SECURITY.md index bad0619..5043a5d 100644 --- a/SECURITY.md +++ b/SECURITY.md @@ -1,80 +1,16 @@ # Security Policy -This document covers all repositories under the [`CitrateNetwork`](https://github.com/CitrateNetwork) GitHub organization. Individual repos may add a repo-specific `SECURITY.md` that **augments** (not replaces) this policy. +## Reporting +Submit vulnerabilities to [security@citrate.ai](mailto:security@citrate.ai). -## Reporting a vulnerability +## Encryption +Public PGP key available at [security@citrate.ai](https://citrate.ai/.well-known/security.txt). -**Do not open a public GitHub issue for security vulnerabilities.** +## Rate Limits +- **Per Host**: 5 requests/second, 10,000 requests/day -Preferred (encrypted, no key exchange): use **GitHub private vulnerability reporting** — on the affected repository, open the **Security** tab → **Report a vulnerability**. This gives a private, GitHub-encrypted channel with no PGP key to fetch. +## Legal +All reports are covered under our [Safe Harbor Policy](https://citrate.ai/legal/safe-harbor). -Alternatively, email **security@citrate.ai**. To encrypt an emailed report, fetch our PGP public key from `keys.openpgp.org` (search `security@citrate.ai`) or via the `Encryption` field of our [`security.txt`](https://citrate.ai/.well-known/security.txt). - -> GH-B-012: the previous PGP path pointed at `keys/security@citrate.ai.asc` in the **private** `citrate-monorepo-archive` repo, which no external reporter can read — the documented encryption path did not work. Use private vulnerability reporting instead. - -Include in your report: -- The repo + commit SHA (or version tag) where you observed the issue -- Steps to reproduce or a proof-of-concept -- Your assessment of the impact severity (critical / high / medium / low) -- Whether you intend public disclosure on any timeline - -We acknowledge within **72 hours** and aim to triage within **5 business days**. For critical vulnerabilities in `citrate-chain` (consensus, execution, on-chain crypto), expect a faster turnaround. - -## Scope - -Severity tiers and audit cadence per repo are documented in each repo's `AUDIT_TIER.md`. The TL;DR: - -| Tier | Audit policy | Vulnerability handling | -|---|---|---| -| **Tier 1** (chain, native app, SDKs, agent-runtime, gateway, compute-pool) | Full audit before every stable release | Coordinated disclosure; CVE assigned for high+ | -| **Tier 3** (docs, and other content/library repos) | Content review only | Triage as docs corrections, no CVE | - -Per-repo tier is authoritative in each repo's `AUDIT_TIER.md`. - -## Responsible disclosure - -We follow a **90-day coordinated disclosure** window. After receiving a report: - -1. **Day 0**: acknowledge receipt within 72 hours. -2. **Day 1-7**: triage, reproduce, classify severity. -3. **Day 7-60**: develop + test fix. -4. **Day 60-75**: prepare release notes, advisory, CVE if applicable. -5. **Day 75-90**: coordinated disclosure window; you and we publish. - -We will **not** pursue legal action against researchers who: -- Report in good faith. -- Avoid privacy violations, data destruction, or service interruption. -- Don't publicly disclose during the coordination window. - -## Out of scope - -- Findings on dependencies (file upstream). -- Best-practice violations without a concrete exploit (e.g., "use of `unsafe` block" without a documented misuse). -- Social engineering of team members. -- Physical access attacks against operator hardware. - -## Supply-chain integrity - -- Crates published from `citrate-chain` are signed via cosign keyless OIDC. See the chain's `.github/workflows/release.yml` for the signing pipeline. -- npm packages from `citrate-sdk-*` are published with provenance attestations. -- SBOMs (CycloneDX) attach to every Tier-1 release. - -Verifying a release artifact: - -```bash -# cosign verify-blob with the issuer / identity from the release -cosign verify-blob --certificate-identity-regexp 'https://github\.com/CitrateNetwork/.*' \ - --certificate-oidc-issuer https://token.actions.githubusercontent.com \ - --signature .sig --certificate .pem \ - -``` - -## Audit firms + history - -Per-repo audit history lives in each repo's `audits/` directory (when present) or in the [`citrate-monorepo-archive`](https://github.com/CitrateNetwork/citrate-monorepo-archive) for pre-split history. The next planned audit is the chain Tier-1 pass before the `v0.5.0` stable tag. - -## Contact - -- Vulnerability reports: security@citrate.ai -- Press/disclosure coordination: same address; tag `[PRESS]` in the subject. -- General questions: open a GitHub Discussion in the relevant repo. +## Known Issues +Publication of known issues will begin at launch with ID: `CITRATE-KNOWN-001` diff --git a/security.txt b/security.txt new file mode 100644 index 0000000..32fd6e0 --- /dev/null +++ b/security.txt @@ -0,0 +1,7 @@ +Contact: security@citrate.ai + +Encryption: https://citrate.ai/keys/security-pgp.asc + +Preferred-Languages: en + +Canonical: https://citrate.ai/.well-known/security.txt