app

Local-first trade for farms and co-ops
git clone https://radroots.dev/git/app.git
Log | Files | Refs | README | LICENSE

SECURITY.md (796B)


      1 # Security policy
      2 
      3 ## Reporting
      4 
      5 Use GitHub private vulnerability reporting when it is available.
      6 
      7 Do not publish secret keys, nsec values, NIP-46 secrets, decrypted private
      8 contracts, or exploitable operational details in a public issue.
      9 
     10 ## Scope
     11 
     12 Security-sensitive areas include:
     13 
     14 - key generation and recovery;
     15 - operating-system keyring custody;
     16 - FFI compatibility;
     17 - native library loading;
     18 - database migrations and recovery;
     19 - operation replay;
     20 - relay transport;
     21 - private Nostr events;
     22 - package provenance;
     23 - dependency policy.
     24 
     25 ## Expectations
     26 
     27 Reports should include:
     28 
     29 - affected commit;
     30 - affected platform;
     31 - reproduction steps that do not expose real secrets;
     32 - expected and observed behaviour;
     33 - impact.
     34 
     35 The project makes no production-readiness claim during the alpha phase.