Security

To report a security vulnerability in monad/clarity or monad/skeleton, email marshal.yung@gaiaco.io directly. Please don't open a public GitHub issue for a suspected vulnerability — that discloses it to everyone before a fix exists.

Scope

This covers vulnerabilities in the framework's own code — monad/clarity and monad/skeleton themselves. It does not cover vulnerabilities in applications built with Monad; report those to whoever built that application.

What to include

  • Which package and release (e.g. monad/clarity, 1.1.0).
  • Steps to reproduce, or a minimal proof of concept.
  • The impact, as you understand it.

What to expect

Monad is currently maintained by one person. Reports are read and triaged personally — there's no fixed response-time commitment and no bug-bounty program. Please give a reasonable amount of time for a fix to ship before disclosing publicly.