Skip to content

Security: devUnixx/Lumigift-lumigift

Security

SECURITY.md

Security Policy

Supported Versions

Version Supported
0.x ✅ Yes

Reporting a Vulnerability

Do not open a public GitHub issue for security vulnerabilities.

Please email security@lumigift.com with:

  1. A description of the vulnerability
  2. Steps to reproduce
  3. Potential impact
  4. Any suggested mitigations

We will acknowledge your report within 48 hours and aim to release a fix within 14 days for critical issues.

Scope

In scope:

  • Smart contract vulnerabilities (fund loss, unauthorized claims)
  • Authentication bypass
  • API injection or data exposure
  • Dependency vulnerabilities with known exploits

Out of scope:

  • Social engineering
  • Denial of service via resource exhaustion
  • Issues requiring physical access to a device

There aren't any published security advisories