The SnellCoin team takes the security of our platform, smart contracts, and user data seriously. We appreciate the responsible disclosure of any vulnerabilities found in this project.
Only the latest main branch is actively supported with security fixes.
| Version | Supported |
|---|---|
main |
✅ |
< 0.2 |
❌ |
If you discover a security vulnerability (such as Supabase RLS policy bypasses, exposed secrets, smart contract flaws, or API injection vectors), please do NOT report it publicly on GitHub Issues.
- GitHub Security Advisory (Preferred): Go to the Security Advisories tab on GitHub and click "Report a vulnerability".
- Direct Email: Alternatively, email the maintainer directly at security@mokan.tech or project leadership.
- A clear description of the vulnerability.
- Steps to reproduce the issue (proof-of-concept code or test scenario).
- Potential impact and severity assessment.
- Any suggested fixes or mitigations.
- Receipt Acknowledgment: We will acknowledge receipt of your report within 48 hours.
- Investigation & Fix: We will investigate the issue and develop a fix in a private branch.
- Release & Credit: Once the patch is deployed to production, we will publish a security advisory and credit you for the responsible disclosure (unless you prefer to remain anonymous).