Zephium treats security as the top priority. A browser is a hostile environment by nature, and we'd rather hear about a problem privately than read about it publicly.
Only the latest release receives security fixes.
| Version | Supported |
|---|---|
| Latest 1.0.0 beta release | Yes |
| Anything older | No |
Do not open a public issue for security problems.
Report privately in either way:
- Use GitHub's private vulnerability reporting.
- Email security@zephium.app.
Include:
- A description of the issue and its impact.
- Steps to reproduce (a proof of concept helps).
- Affected version / commit, and your platform (macOS or Windows).
We'll keep you updated and credit you in the release notes unless you'd rather stay anonymous.
Please give us a reasonable window to fix the issue before any public disclosure. We practice coordinated disclosure and won't take legal action against good-faith research.