Do not open public issues for suspected vulnerabilities, exposed credentials, or bugs that could put funds at risk. Use this repository's enabled GitHub private Report a vulnerability form under the Security tab. If GitHub is unavailable, contact a repository owner through an already-established private channel before disclosure. Do not include live keys or exploit deployed contracts while preparing a report.
Reports should include affected commit/version, impact, reproduction steps, and suggested remediation. Maintainers will acknowledge receipt and coordinate a responsible disclosure timeline; no response-time SLA is currently promised.
Only the contracts/cw-reality package is executable maintained code today.
depricated_ui/ and scripts/unsafe/ are unsupported historical material.