Skip to content

Security: lily-protocol/lily-contracts

Security

SECURITY.md

Security Policy

Supported scope

This repository contains smart contract infrastructure and supporting contributor workflows for Lily Protocol on Stellar. Security-sensitive areas include:

  • Contract authorization logic
  • Storage layouts and upgrade assumptions
  • Settlement state transitions
  • Admin and initialization paths
  • Build and deployment workflows

Reporting a vulnerability

Please do not file public GitHub issues for vulnerabilities that could put funds, permissions, or protocol integrity at risk.

Report security issues privately to:

  • security@lilyprotocol.com

Include:

  • Affected contract or crate
  • Impact summary
  • Reproduction steps or proof of concept
  • Suggested mitigations if known

We will acknowledge receipt as quickly as possible and coordinate next steps privately.

There aren't any published security advisories