Do not open a public GitHub issue for security vulnerabilities.
Please report security vulnerabilities to the Ava Labs security team at security@avalabs.org. Include as much detail as possible:
- A description of the vulnerability and its potential impact
- Steps to reproduce or a proof-of-concept
- Any suggested mitigations
You can expect an acknowledgement within 2 business days and a resolution timeline within 7 business days of triage.
This policy covers the reforge library and its CI/CD pipeline. Vulnerabilities
in the Foundry submodule should be reported upstream to the
Foundry project.
Only the latest release on the main branch is supported.