| Version | Supported |
|---|---|
main branch |
✅ Active |
| Older branches | ❌ |
Please do not open a public GitHub issue for security vulnerabilities.
If you discover a security vulnerability in this project — including issues affecting the WebAuthn passkey flow, session JWT, or smart-contract interactions — please report it privately:
- GitHub Security Advisories (preferred): Navigate to the Security tab → Report a vulnerability on this repository.
- Email fallback: Send details to the maintainers via the org contact in the GitHub profile.
- A description of the vulnerability and its impact
- Steps to reproduce (as detailed as possible)
- Any proof-of-concept or exploit code
- Your suggested fix if you have one
| Milestone | Target |
|---|---|
| Acknowledgement | Within 48 hours |
| Assessment & severity rating | Within 5 business days |
| Fix & coordinated disclosure | Within 30 days (severity-dependent) |
We take security seriously. Thank you for helping keep Guardian Wallet safe.