Cella handles governance workflows that can culminate in on-chain submissions, so we take security seriously and appreciate responsible disclosure.
Please do not open a public issue for security vulnerabilities.
Report privately to info@awen.online (or, if you use GitHub, via the repository's "Report a vulnerability" / private security advisory feature under the Security tab).
Please include:
- A description of the vulnerability and its potential impact.
- Steps to reproduce or a proof of concept.
- Affected version(s) / commit, and any relevant configuration.
- Acknowledgement within 5 business days.
- An initial assessment and severity triage shortly after.
- Coordinated disclosure: we will work with you on a fix and a disclosure timeline, and credit you (if desired) once a fix is released.
Security issues in Cella's code, dependencies, and default configuration are in scope. Issues in third-party services (LLM providers, Cardano infrastructure) should be reported to those providers, though we welcome a heads-up if they affect Cella users.
Until a tagged release exists, the main branch is the supported version. This section will list supported release lines once Cella reaches a stable release.