Skip to content

docs: add SECURITY.md (private disclosure + soundness scope)#12

Merged
Sbcdn merged 1 commit into
mainfrom
dev
Jun 25, 2026
Merged

docs: add SECURITY.md (private disclosure + soundness scope)#12
Sbcdn merged 1 commit into
mainfrom
dev

Conversation

@Sbcdn

@Sbcdn Sbcdn commented Jun 25, 2026

Copy link
Copy Markdown
Collaborator

Adds a security policy for the public repository:

  • Private vulnerability reporting (GitHub Security tab, or email).
  • Scope: the soundness invariant — dwarf must never accept a certificate or
    lottery ticket that upstream Mithril rejects — and the hashed-byte equivalence
    contract enforced by the harness.
  • Out of scope: the documented intentional divergences (registry-pinned), the
    U2048 lottery wide-fallback ceiling (aborts, never falsely accepts), the
    assumed-correct crypto primitives, and host-only tooling.

No code changes.

@Sbcdn Sbcdn merged commit 17708a8 into main Jun 25, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant