Skip to content

Security: besiwims/cella

Security

SECURITY.md

Security Policy

Cella handles governance workflows that can culminate in on-chain submissions, so we take security seriously and appreciate responsible disclosure.

Reporting a vulnerability

Please do not open a public issue for security vulnerabilities.

Report privately to info@awen.online (or, if you use GitHub, via the repository's "Report a vulnerability" / private security advisory feature under the Security tab).

Please include:

  • A description of the vulnerability and its potential impact.
  • Steps to reproduce or a proof of concept.
  • Affected version(s) / commit, and any relevant configuration.

What to expect

  • Acknowledgement within 5 business days.
  • An initial assessment and severity triage shortly after.
  • Coordinated disclosure: we will work with you on a fix and a disclosure timeline, and credit you (if desired) once a fix is released.

Scope

Security issues in Cella's code, dependencies, and default configuration are in scope. Issues in third-party services (LLM providers, Cardano infrastructure) should be reported to those providers, though we welcome a heads-up if they affect Cella users.

Supported versions

Until a tagged release exists, the main branch is the supported version. This section will list supported release lines once Cella reaches a stable release.

There aren't any published security advisories