Skip to content

Security: thenamespace/metadata-service

Security

SECURITY.md

Security policy

Reporting a vulnerability

Please report suspected vulnerabilities privately through GitHub Security Advisories. Do not include sensitive details in a public issue.

Include, when possible:

  • the affected endpoint or component;
  • steps to reproduce the issue;
  • the security impact;
  • any suggested mitigation;
  • whether the issue is already public or actively exploited.

Please allow maintainers time to investigate before disclosing the issue publicly. We will use the advisory to coordinate questions, remediation, and disclosure.

Scope

Security reports are especially useful for:

  • SIWE replay, signature, scope, or chain-validation bypasses;
  • ENS ownership-verification bypasses;
  • unauthorized media reads, writes, or deletions;
  • malicious file-processing behavior;
  • secret or personal-data exposure;
  • denial-of-service paths that bypass documented limits.

General bugs and feature requests can be filed through the repository's public issue tracker.

There aren't any published security advisories