Updated Security Policy aligned with your Gardens bug bounty pool mechanics and requirements:
Gardens v2 is a modular governance framework that enables communities to create and manage multiple governance pools with customizable parameters and voting mechanisms. We take security seriously and are committed to protecting our users and their communities.
Gardens v2 is currently deployed on the following networks:
| Network | Status | Support |
|---|---|---|
| Gnosis Chain | ✅ Active | Full support |
| Polygon | ✅ Active | Full support |
| Arbitrum | ✅ Active | Full support |
| Optimism | ✅ Active | Full support |
| Base | ✅ Active | Full support |
| Celo | ✅ Active | Full support |
| Ethereum | ✅ Active | Full support |
We provide security support for all currently deployed networks.
Gardens v2 operates an on-chain bug bounty program through a dedicated funding pool:
This pool rewards responsible disclosure of vulnerabilities affecting Gardens v2 smart contracts currently deployed and actively used on:
Eligible vulnerabilities include:
- Smart contracts developed by Gardens Core Contributors
- Contracts integrated into Gardens that may impact user funds or governance outcomes (evaluated case-by-case)
Out-of-scope:
- Front-end or UI-only bugs
- Previously reported vulnerabilities
- Issues in unused or deprecated contracts
For concrete examples of intended-design, non-production, and duplicate report categories, see Known Non-Eligible Findings.
Before reporting a new issue, review existing advisories and acknowledged decisions:
- GitHub Security Advisories: https://github.com/1Hive/gardens-v2/security/advisories
- Advisory History: ./security/advisory-history.md
Duplicate reports are not eligible for rewards.
Researchers should also review Known Non-Eligible Findings before submitting a report.
All vulnerabilities must first be reported via GitHub Security Advisories:
Do not create public issues.
To remain eligible for rewards:
- Do not disclose the vulnerability to any third party before reporting
- Do not exploit the vulnerability
- Do not publish or share proof publicly before coordinated disclosure
Any violation will result in disqualification from the bounty.
Reports should include:
- Description of the vulnerability
- Impact and potential exploit scenarios
- Steps to reproduce
- Affected contracts and networks
- Proof of concept (if applicable)
After submission:
- Core Contributors will review and validate the report
- Severity will be assessed using the CVSS Risk Rating scale
- The team will coordinate remediation with the reporter
- If eligible, the reporter will be invited to submit a funding proposal in the bounty pool
Rewards are determined as a percentage of the total pool funds:
| Severity | CVSS Score | Reward |
|---|---|---|
| Critical | 9.0 – 10.0 | 50% of pool funds |
| High | 7.0 – 8.9 | 10% of pool funds |
| Medium | 4.0 – 6.9 | 1% of pool funds |
Notes:
- Final severity assessment is determined by Core Contributors
- Evaluation may include contextual and systemic impact beyond raw CVSS score
- Rewards scale dynamically with pool size
- Start with small amounts to test functionality
- Carefully review governance parameters before deployment
- Ensure trusted participants in privileged roles
- Monitor activity and proposals regularly
- Use trusted wallets only
- Verify the official app: https://app.gardens.fund
- Start with small stakes
- Keep wallet software updated
- Test on testnets before mainnet deployment
- Follow smart contract security best practices
- Stay updated with releases and advisories
Gardens v2 integrates external protocols:
- Allo Protocol v2
- The Graph
- Safe
Security assumptions extend to these dependencies.
Security updates are communicated via:
- Twitter: https://twitter.com/gardens_fund
- Discord: https://discord.gg/tJWPg69ZWG
- Participate in audits and code reviews
- Report vulnerabilities responsibly
- Improve documentation and tooling
See: ./CONTRIBUTING.md
Licensed under GPL-3.0.
Use of Gardens v2 involves risks inherent to experimental blockchain systems. Users assume responsibility for their usage.