deso-protocol / deso-protocol/core

Security contact needed — published bug bounty email is inactive

Open
#1,476 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
Go
Stars
327
Forks
106
PR merge metrics
No merged PRs in 30d

Description

Hi DeSo maintainers,

I have a security vulnerability affecting a currently deployed DeSo component.

I’m trying to disclose it responsibly and privately, but the security / bug-bounty email currently listed in the DeSo documentation is no longer accepting mail. I also tried other historical DeSo contact addresses, but they are inactive as well.

Could a current maintainer please provide an active private security contact, or enable GitHub Private Vulnerability Reporting for the relevant repository?

I have a complete technical report and reproducible PoC ready to provide privately.

I will not post vulnerability details publicly.

I would also appreciate confirmation on whether the published DeSo bug-bounty program is still active before I send the full report.

Thanks.

Contributor guide

No contributing guide indexed for this repository

Research direction

The issue names the published DeSo security or bug-bounty contact but no repository file or test. Start by reviewing the documented contact and the repository's private vulnerability reporting settings; done means a maintainer confirms an active private channel or enables reporting and corrects the published information.

Written by the indexing model from the issue text.

Assessment

Domain
security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Active
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.