This policy applies to every repository in the Consensys-Incorporated GitHub organization. Where a
repository publishes its own SECURITY.md, that policy takes precedence over this one.
Report vulnerabilities privately by email to Security-Report@Consensys.com.
Where a repository offers it, you can instead open its Security tab and select Report a vulnerability (GitHub private vulnerability reporting). This option exists only on actively maintained public repositories; if you do not see the button, use email.
Do not report security issues through public issues, pull requests, or discussions.
- The affected repository and the version, tag, or commit you tested.
- A description of the issue and its potential impact.
- Steps to reproduce, or a proof of concept.
- How we can reach you, and whether and how you would like to be credited.
We acknowledge every report, keep you informed during triage and remediation, and agree on a disclosure timeline with you. Please allow us reasonable time to investigate and release a fix before any public disclosure. We credit reporters who wish to be named.
Consensys will not pursue or support legal action against researchers who act in good faith and in accordance with this policy. Acting in good faith means that you:
- Only access, modify, or store data that is your own or that you have explicit permission to test with.
- Avoid privacy violations, data destruction, and degradation or disruption of services.
- Do not use social engineering, phishing, or physical attacks.
- Stop testing and report immediately if you encounter personal or otherwise sensitive data.
- Report vulnerabilities in third-party dependencies to their maintainers.
- MetaMask products are covered by the MetaMask organization and its security policy.
- Projects hosted by other organizations, such as LF Decentralized Trust, follow the policy published in their own repositories.
- This policy does not by itself establish a bug bounty program. Where a project runs one, its own security policy says so.
- For support questions and bugs without a security impact, use the repository's issue tracker.