Skip to content

Security: ava-labs/reforge

SECURITY.md

Security Policy

Reporting a Vulnerability

Do not open a public GitHub issue for security vulnerabilities.

Please report security vulnerabilities to the Ava Labs security team at security@avalabs.org. Include as much detail as possible:

  • A description of the vulnerability and its potential impact
  • Steps to reproduce or a proof-of-concept
  • Any suggested mitigations

You can expect an acknowledgement within 2 business days and a resolution timeline within 7 business days of triage.

Scope

This policy covers the reforge library and its CI/CD pipeline. Vulnerabilities in the Foundry submodule should be reported upstream to the Foundry project.

Supported Versions

Only the latest release on the main branch is supported.

There aren't any published security advisories