If you discover a security vulnerability in Finchippay-Solution, please report it privately to the maintainers.
Do not open a public issue. Instead, email the team with details.
- Reporting: Vulnerability reported privately via email
- Triage: Maintainers assess severity within 48 hours
- Fix: Patch developed and tested
- Disclosure: Public advisory published after fix is deployed
- npm audit runs on every PR for frontend and backend (--audit-level=high)
- cargo audit runs on every PR for the Soroban contract
- Dependabot opens weekly PRs for npm and cargo dependency updates
- Weekly security audit workflow runs on schedule (.github/workflows/security-audit.yml)
| Version | Supported |
|---|---|
| latest | ✅ |
| < 1.0 | ❌ |