We recommend using the latest version of each crate for security updates.
We take the security of the Parwana seriously. If you believe you have found a security vulnerability, please report it to us as described below.
Please do NOT report security vulnerabilities through public GitHub issues.
Instead, please report them via email to security@csv-protocol.org with:
- A description of the issue
- Steps to reproduce the issue
- Affected versions
- Any relevant logs, screenshots, or proof-of-concept code
- Submit your report via email
- You will receive a confirmation within 48 hours
- We will investigate and determine our response within 7 days
- We will release a fix and update the changelog
We prefer all communications to be in English.
This security policy applies to all crates in the Parwana workspace:
- csv-core
- csv-runtime
- csv-sdk
- csv-cli
- csv-wallet
- csv-keys
- csv-store
- csv-p2p
- csv-observability
- csv-adapters/csv-bitcoin
- csv-adapters/csv-ethereum
- csv-adapters/csv-solana
- csv-adapters/csv-sui
- csv-adapters/csv-aptos
- csv-adapters/csv-celestia