Skip to content

Security: caravan-bitcoin/caravan

SECURITY.md

Security Policy

Reporting a Vulnerability

Please do not open a public GitHub issue for security bugs.

Report vulnerabilities privately using one of:

  1. Preferred: email caravan@unchained.com
  2. GitHub private vulnerability reporting

What to include

  • A clear description of the issue and its impact
  • Affected packages or versions, if known
  • Steps to reproduce, or a proof of concept when possible

Scope

In scope

The Caravan Coordinator app and @caravan/* packages in this monorepo

Out of scope

  • Third-party hardware wallet firmware
  • External block explorer or API services

Supported Versions

Security fixes target the latest release on main and the corresponding published npm packages. We do not maintain a separate long-term support matrix.

There aren't any published security advisories