Skip to content

misc: Simplify SECURITY.md - #1011

Open
2dvorak wants to merge 1 commit into
kaiachain:devfrom
2dvorak:update-security-md
Open

misc: Simplify SECURITY.md#1011
2dvorak wants to merge 1 commit into
kaiachain:devfrom
2dvorak:update-security-md

Conversation

@2dvorak

@2dvorak 2dvorak commented Aug 4, 2026

Copy link
Copy Markdown
Contributor

Proposed changes

Reduce SECURITY.md to the essentials:

  • Supported versions: report against the dev branch
  • Do not disclose publicly, before or after reporting
  • Link to the HackenProof bug bounty program

and let the HackenProof program page carry the details (e.g., the scope and out-of-scope lists, reward criteria, and program rules are maintained on the program page).

Types of changes

  • 🐛 Bug fix
  • ✨ Non-hardfork changes (node upgrade not required)
  • 💥 Hardfork / consensus-breaking changes
  • 🧪 Test improvements
  • 🧰 CI / build tool
  • ♻️ Chore / Refactor / Non-functional changes

Checklist

  • 📖 I have read the CONTRIBUTING GUIDELINES doc
  • 📝 I have signed in the PR comment I have read the CLA Document and I hereby sign the CLA in first time contribute after having read CLA
  • 🟢 Lint and unit tests pass locally with my changes ($ make test)

Related issues

Further comments

Reduce SECURITY.md to the essentials and let the HackenProof program page
carry the details, following go-ethereum's approach:

- Supported versions: report against the dev branch
- Do not disclose publicly, before or after reporting
- Link to the bug bounty program

The scope and out-of-scope lists, reward criteria, and program rules are
maintained on the program page, so keeping copies here only let them drift.
The Kaia Web section is also removed: that program has ended.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@2dvorak 2dvorak self-assigned this Aug 4, 2026
@2dvorak 2dvorak added the do not merge Do not merge just yet label Aug 4, 2026
@2dvorak
2dvorak marked this pull request as ready for review August 4, 2026 11:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

do not merge Do not merge just yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants