Skip to content

Security: 21-DOT-DEV/swift-secp256k1

SECURITY.md

Security Policy

Reporting a Vulnerability

To report a security vulnerability in swift-secp256k1, please use GitHub Security Advisories.

Do not file a public issue.

When reporting, please include:

  • A description of the vulnerability
  • Steps to reproduce or a proof of concept
  • Potential impact assessment

We will acknowledge receipt within 7 days and provide an initial assessment as soon as possible.

Supported Versions

This package is pre-1.0 (SemVer major version zero). Only the latest minor release receives security fixes.

Version Supported
0.23.x
< 0.23

Upstream Dependencies

This package wraps libsecp256k1 and libsecp256k1-zkp via Swift's C interoperability.

Vulnerabilities in the underlying C libraries should be reported directly to their respective projects:

There aren’t any published security advisories