This document outlines security procedures and general policies for the Libra project.
Note: As Libra Core is currently in the prototype stage and does not power a blockchain with a currency that has real-world value, our security procedures are not fully in place. We will release a more complete disclosure policy prior to the launch of the mainnet.
Reporting a Bug
The Libra team and community take all security bugs in the Libra project seriously. Thank you for improving the security of Libra. We appreciate your efforts and responsible disclosure. We will make every effort to acknowledge your contributions.
Report security bugs by emailing firstname.lastname@example.org.
A member of the security team will acknowledge your email. After the initial reply to your report is sent, the security team will try to keep you informed on the progress towards a fix and a full announcement. The security team may ask you for additional information or guidance.
When the security team receives a security bug report, they will assign it to a primary handler. The primary handler will coordinate the fix and release process which involves the following steps:
- Confirm the problem and determine the affected versions.
- Audit code to find any potential similar problems.
- Prepare fixes for all releases that are still under maintenance.
Comments on This Policy
If you have suggestions on how this process could be improved, please submit a pull request.