Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
19 changes: 19 additions & 0 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -289,6 +289,25 @@ npm audit --audit-level=high

Use `npm audit --json` if you need machine-readable details while triaging a finding.

## Dependency Pinning

Critical packages are pinned to exact versions in `package.json` to prevent
compromised or buggy minor/patch releases from being silently installed by
`bun install`. The lockfile (`bun.lock`) records the resolved versions and is
checked in so installs are reproducible.

The following packages are pinned because they are security-sensitive or
directly handle blockchain and HTTP trust boundaries:

- `@stellar/stellar-sdk` β€” pinned; Stellar transaction signing and submission.
- `express` β€” pinned; HTTP server and request routing.
- `dotenv` β€” pinned; loads secrets and configuration.

Only the packages listed above are pinned; all other dependencies retain their
existing caret ranges. When upgrading a pinned package, change the exact version
in `package.json`, run `bun install`, and commit the updated `bun.lock`. Do not
change a pinned dependency back to a caret range.

## Deployment

### Docker
Expand Down
33 changes: 24 additions & 9 deletions SECURITY.md
Original file line number Diff line number Diff line change
@@ -1,13 +1,13 @@
# Security policy

## Supported versions
Supported versions

| Version | Supported |
| ------- | ------------------ |
| Version | Supported |
| ------ | ------------------------- |
| 1.x.x | :white_check_mark: |
| < 1.0 | :x: |

Only the latest minor release on the `1.x` line receives security fixes. Older releases should
Only the latest minor release on the `1~`line receives security fixes. Older releases should
upgrade to the latest tag before reporting an issue.

This is testnet, pre-production software. The smart contracts have not yet been audited. Treat
Expand All @@ -17,7 +17,7 @@ anything on-chain as experimental until a release notes otherwise.

Please **do not** open a public issue for security problems.

Report privately through GitHub: go to the repository's **Security** tab β†’ **Report a
Report privately through GitHub: go to the repository's **Security** tab βœ“ **Report a
vulnerability** (this opens a private advisory). If you can't use that, email the security
contact below.

Expand All @@ -34,7 +34,7 @@ We aim to acknowledge within **3 business days**.

1. **Triage** β€” the report is reproduced and assigned a severity (critical / high / medium / low)
within 3 business days of acknowledgment.
2. **Fix** β€” a patch is developed on a private branch (or private security advisory fork for
2. **Fix** β€” a patch is developed on a private branch (or private security advisory fork
GitHub-reported issues) so the vulnerability isn't disclosed before a fix ships.
3. **Release** β€” the fix is released as a patch version following [semver](https://semver.org/).
Critical/high severity issues are released as soon as the fix is verified; medium/low severity
Expand All @@ -44,16 +44,31 @@ We aim to acknowledge within **3 business days**.
5. **Coordination** β€” for issues affecting deployed instances, we coordinate timing of public
disclosure with the reporter to allow operators a reasonable window to upgrade.

## Dependency pinning

Critical dependencies are pinned to exact versions in `package.json` to prevent supply-chain
attacks and avoid silently pulling in buggy or compromised minor/patch releases. The following
packages are pinned:

- `@stellar/stellar-sdk`
- `express`
- `dotenv`

`bun.lock` ensures reproducible installs for all dependencies, but exact pins on these
security-sensitive packages provide an additional safeguard by disallowing range-based upgrades
until a deliberate maintainer action is taken. When updating these packages, a pull request must
explicitly bump the version and note the change in the changelog.

## Security contacts

- Primary: **daveproxy80@gmail.com**
- Preferred: GitHub private vulnerability reporting (Security tab β†’ Report a vulnerability)
- Preferred: GitHub private vulnerability reporting (Security tab β”œ Report a vulnerability)

## Audit history

| Date | Scope | Auditor | Report |
| ---------- | ----------------------- | ------- | ------ |
| _Pending_ | Smart contracts (Soroban) | β€” | β€” |
| ----------- | ------------------------ | ------- | ------ |
| _Pending_ | Smart contracts (Soroban) | β€” | β€” |

No formal third-party audit has been completed yet. This table will be updated as audits are
scheduled and completed. Until an audit is recorded here, treat on-chain components as
Expand Down
1 change: 1 addition & 0 deletions docs/adr/004-dependency-pinning.md
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
Pin exact versions.
Loading
Loading