This repository is intended for engineering research and education.
Please do not open public issues for undisclosed vulnerabilities.
Instead, report privately to project maintainers with:
- affected component and path
- impact summary
- reproduction steps
- suggested mitigation (if available)
- Never commit private keys, tokens, RPC credentials, or signed payloads.
- Use
config/.env.exampleas template only. - Keep runtime secrets in local
.envfiles excluded by.gitignore.
Before releases and major PRs:
- Run build/test/lint gates.
- Re-check config defaults for unsafe values.
- Verify no sensitive values exist in docs, scripts, or examples.
- Validate deployment scripts against target chain and account scopes.