Skip to content

Security: Mattdgn/pm-amm

Security

SECURITY.md

Security Policy

Scope

This policy covers:

  • Anchor program (anchor/programs/pm_amm/) — on-chain smart contract
  • API routes (app/src/app/api/) — server-side endpoints
  • Math implementation (pm_math.rs, accrual.rs) — financial calculations

Reporting a Vulnerability

Please report security vulnerabilities by emailing github.com.mattdgn.p.demeanor108@passmail.net.

  • Do not open a public issue for security vulnerabilities.
  • Include steps to reproduce and potential impact.
  • You will receive an acknowledgment within 48 hours.

Bug Bounty

No formal bug bounty program exists at this time. We appreciate responsible disclosures and will credit reporters in our changelog.

Out of Scope

  • Devnet-only issues (test environment)
  • Social engineering
  • Denial of service against public RPC endpoints
  • Issues in third-party dependencies (report upstream)

There aren't any published security advisories