Skip to content

security: publish community vulnerability disclosure and triage policy #285

Description

@TheNewAutonomy

Parent epic: #262

Define the pre-launch security disclosure and triage workflow for a no-budget, community-review launch model.

Why

Catalyst plans to launch without paid external audit/pen-test services. We need a clear, operator-facing and contributor-facing process for responsible disclosure and deterministic remediation handling.

Deliverables

Definition of done

  • Policy documented in docs/ and linked from docs/README.md
  • Workflow references existing mainnet security gates (#272, #273, #280)
  • Tracker issue mainnet: launch readiness program tracker #260 updated to include this requirement in launch criteria

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions