Skip to content

security: publish community vulnerability disclosure and triage policy #285

@TheNewAutonomy

Description

@TheNewAutonomy

Parent epic: #262

Define the pre-launch security disclosure and triage workflow for a no-budget, community-review launch model.

Why

Catalyst plans to launch without paid external audit/pen-test services. We need a clear, operator-facing and contributor-facing process for responsible disclosure and deterministic remediation handling.

Deliverables

Definition of done

  • Policy documented in docs/ and linked from docs/README.md
  • Workflow references existing mainnet security gates (#272, #273, #280)
  • Tracker issue mainnet: launch readiness program tracker #260 updated to include this requirement in launch criteria

Metadata

Metadata

Assignees

No one assigned

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions