Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
24 changes: 24 additions & 0 deletions BOUNTY.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,24 @@
# Citrate Network Bounty Program

## Rewards
| Severity | Reward (USD) |
|-----------|--------------|
| Critical | 50,000 |
| High | 10,000 |
| Medium | 2,500 |
| Low | 500 |

## Launch Details
- **Launch Date**: 2024-06-15
- **Payout Method**: Multi-signature wallet (2/3)
- **Currency**: USDC
- **KYC Requirement**: Mandatory for payouts > $1,000
- **Eligibility**: Open to all except Citrate employees/contractors

## Payout Process
1. Submit vulnerability report via [security@citrate.ai](mailto:security@citrate.ai)
2. Undergo KYC verification if applicable
3. Receive USDC payout to verified address

## Encryption
**PGP Key**: [security@citrate.ai](https://citrate.ai/.well-known/security.txt)
84 changes: 10 additions & 74 deletions SECURITY.md
Original file line number Diff line number Diff line change
@@ -1,80 +1,16 @@
# Security Policy

This document covers all repositories under the [`CitrateNetwork`](https://github.com/CitrateNetwork) GitHub organization. Individual repos may add a repo-specific `SECURITY.md` that **augments** (not replaces) this policy.
## Reporting
Submit vulnerabilities to [security@citrate.ai](mailto:security@citrate.ai).

## Reporting a vulnerability
## Encryption
Public PGP key available at [security@citrate.ai](https://citrate.ai/.well-known/security.txt).

**Do not open a public GitHub issue for security vulnerabilities.**
## Rate Limits
- **Per Host**: 5 requests/second, 10,000 requests/day

Preferred (encrypted, no key exchange): use **GitHub private vulnerability reporting** — on the affected repository, open the **Security** tab → **Report a vulnerability**. This gives a private, GitHub-encrypted channel with no PGP key to fetch.
## Legal
All reports are covered under our [Safe Harbor Policy](https://citrate.ai/legal/safe-harbor).

Alternatively, email **security@citrate.ai**. To encrypt an emailed report, fetch our PGP public key from `keys.openpgp.org` (search `security@citrate.ai`) or via the `Encryption` field of our [`security.txt`](https://citrate.ai/.well-known/security.txt).

> GH-B-012: the previous PGP path pointed at `keys/security@citrate.ai.asc` in the **private** `citrate-monorepo-archive` repo, which no external reporter can read — the documented encryption path did not work. Use private vulnerability reporting instead.

Include in your report:
- The repo + commit SHA (or version tag) where you observed the issue
- Steps to reproduce or a proof-of-concept
- Your assessment of the impact severity (critical / high / medium / low)
- Whether you intend public disclosure on any timeline

We acknowledge within **72 hours** and aim to triage within **5 business days**. For critical vulnerabilities in `citrate-chain` (consensus, execution, on-chain crypto), expect a faster turnaround.

## Scope

Severity tiers and audit cadence per repo are documented in each repo's `AUDIT_TIER.md`. The TL;DR:

| Tier | Audit policy | Vulnerability handling |
|---|---|---|
| **Tier 1** (chain, native app, SDKs, agent-runtime, gateway, compute-pool) | Full audit before every stable release | Coordinated disclosure; CVE assigned for high+ |
| **Tier 3** (docs, and other content/library repos) | Content review only | Triage as docs corrections, no CVE |

Per-repo tier is authoritative in each repo's `AUDIT_TIER.md`.

## Responsible disclosure

We follow a **90-day coordinated disclosure** window. After receiving a report:

1. **Day 0**: acknowledge receipt within 72 hours.
2. **Day 1-7**: triage, reproduce, classify severity.
3. **Day 7-60**: develop + test fix.
4. **Day 60-75**: prepare release notes, advisory, CVE if applicable.
5. **Day 75-90**: coordinated disclosure window; you and we publish.

We will **not** pursue legal action against researchers who:
- Report in good faith.
- Avoid privacy violations, data destruction, or service interruption.
- Don't publicly disclose during the coordination window.

## Out of scope

- Findings on dependencies (file upstream).
- Best-practice violations without a concrete exploit (e.g., "use of `unsafe` block" without a documented misuse).
- Social engineering of team members.
- Physical access attacks against operator hardware.

## Supply-chain integrity

- Crates published from `citrate-chain` are signed via cosign keyless OIDC. See the chain's `.github/workflows/release.yml` for the signing pipeline.
- npm packages from `citrate-sdk-*` are published with provenance attestations.
- SBOMs (CycloneDX) attach to every Tier-1 release.

Verifying a release artifact:

```bash
# cosign verify-blob with the issuer / identity from the release
cosign verify-blob --certificate-identity-regexp 'https://github\.com/CitrateNetwork/.*' \
--certificate-oidc-issuer https://token.actions.githubusercontent.com \
--signature <artifact>.sig --certificate <artifact>.pem \
<artifact>
```

## Audit firms + history

Per-repo audit history lives in each repo's `audits/` directory (when present) or in the [`citrate-monorepo-archive`](https://github.com/CitrateNetwork/citrate-monorepo-archive) for pre-split history. The next planned audit is the chain Tier-1 pass before the `v0.5.0` stable tag.

## Contact

- Vulnerability reports: security@citrate.ai
- Press/disclosure coordination: same address; tag `[PRESS]` in the subject.
- General questions: open a GitHub Discussion in the relevant repo.
## Known Issues
Publication of known issues will begin at launch with ID: `CITRATE-KNOWN-001`
7 changes: 7 additions & 0 deletions security.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,7 @@
Contact: security@citrate.ai

Encryption: https://citrate.ai/keys/security-pgp.asc

Preferred-Languages: en

Canonical: https://citrate.ai/.well-known/security.txt