Skip to content

security: publish community vulnerability disclosure and triage policy #285

@TheNewAutonomy

Description

@TheNewAutonomy

Parent epic: #262

Define the pre-launch security disclosure and triage workflow for a no-budget, community-review launch model.

Why

Catalyst plans to launch without paid external audit/pen-test services. We need a clear, operator-facing and contributor-facing process for responsible disclosure and deterministic remediation handling.

Deliverables

Definition of done

  • Policy documented in docs/ and linked from docs/README.md
  • Workflow references existing mainnet security gates (#272, #273, #280)
  • Tracker issue mainnet: launch readiness program tracker #260 updated to include this requirement in launch criteria

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions