Skip to content

Security: NeaBouli/TrueRepublic

Security

.github/SECURITY.md

Security Policy

Supported Versions

Version Supported
0.1.x Yes

Reporting a Vulnerability

DO NOT open a public GitHub issue for security vulnerabilities.

Responsible Disclosure

  1. Email: security@truerepublic.network
  2. Include:
    • Description of the vulnerability
    • Steps to reproduce
    • Potential impact
    • Affected component (blockchain, contracts, wallets)
  3. You will receive acknowledgment within 48 hours.

Scope

  • Blockchain consensus and validator logic
  • Smart contract security (CosmWasm)
  • Token handling and treasury operations
  • Wallet key management
  • API and RPC endpoint security

Out of Scope

  • Social engineering
  • DDoS attacks
  • Issues in third-party dependencies (report upstream)

Bug Bounty

Rewards are paid in PNYX based on severity:

Severity Reward
Critical 10,000 PNYX
High 5,000 PNYX
Medium 1,000 PNYX
Low 500 PNYX

There aren't any published security advisories