Vulnerability Reporting
The SLASettle maintainers take the security of smart contracts, off-chain infrastructure, and client applications seriously. We welcome responsible disclosure of potential security vulnerabilities.
Scope
The following repositories and components fall within our security disclosure scope:
SLASettleHQ/slasettle-vault:watcher_registrycontract logic and authorization boundaries.sla_vaultescrow management, token accounting, and settlement logic.
SLASettleHQ/slasettle-hub:@slasettle/sdktransaction construction and simulation logic.apps/webwallet integration and network safety controls.services/indexerREST API, CORS boundaries, and database query handling.services/watchercryptographic signing and transaction submission loop.
Reporting Procedure
To report a vulnerability responsibly:
- Private GitHub Security Advisory:
- Navigate to the Security tab of the relevant repository (
slasettle-vaultorslasettle-hub). - Click Report a vulnerability to open a confidential security advisory draft.
- Navigate to the Security tab of the relevant repository (
- Alternative Contact:
- If GitHub Security Advisories are inaccessible, open a minimal issue on GitHub requesting a private communication channel. Do not post exploit code, proof-of-concept scripts, or reproduction payloads in public issues.
Report Contents
Please include the following information in your advisory:
- Detailed description of the vulnerability and its potential impact.
- Step-by-step reproduction instructions or a minimal test case.
- Affected contract addresses, function names, or file paths.
- Proposed remediation or patch, if available.
Response Timeline & Expectations
- Initial Acknowledgment: Within 48 hours of receipt.
- Triage & Assessment: Within 5 business days, confirming vulnerability validity and severity.
- Remediation & Disclosure: Coordinated patch deployment to Testnet contracts and public release notes following resolution.
Current Security Status & Caveats
- Testnet Status: The SLASettle protocol is currently deployed exclusively to Stellar Testnet.
- Audit Status: The codebase has undergone comprehensive automated testing (416 tests) and internal static analysis, but has not yet completed a formal external third-party security audit.
- No Active Bug Bounty: As an open-source testnet research project, monetary bug bounties are not currently offered. We gratefully credit security researchers in our release notes and changelogs.