Skip to content

Security Vulnerability Report Inquiry — Contact Channel #835

Description

@Taolaw

Hi Gear team,

I'm an independent security researcher. While researching gear-bridges (the Vara ↔ Ethereum bridge), I identified a potential
security issue that I'd like to report to you under responsible disclosure.

I couldn't find a SECURITY.md or a security contact email in the repository, so I'm opening this issue to confirm:

  1. Do you have a dedicated email or channel for receiving external security vulnerability reports?
  2. Do you run a bug bounty / vulnerability reward program?

To avoid information exposure, this issue contains no technical details. Once the contact channel is confirmed, I'll submit the
full report through it (description, root cause, impact, PoC, and remediation suggestions).

The issue is not public and will stay strictly confidential until a mutually agreed disclosure date. Regarding reward: this
research took substantial time and effort, and I'd appreciate my work being recognized accordingly; but regardless of any reward,
I'll honor responsible disclosure and cooperate through to remediation.

Thanks!

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions