Only the current main branch is supported. ZechLedger is testnet-only and must not be used with assets of real value.
Use the repository’s Security → Report a vulnerability flow to open a private GitHub Security Advisory. Do not include wallet seeds, spending keys, UFVKs, RPC cookies, admin tokens, audit private keys, or real accounting data in the report.
Include the affected commit, impact, reproduction steps, and a minimal redacted proof. Please avoid opening a public issue until a fix is available.
If private vulnerability reporting is unavailable, contact the repository owner through the private channel that granted repository access. A public issue may request a security contact, but must not contain vulnerability details.
Reports will normally be acknowledged within five business days. Remediation and coordinated disclosure timing depend on severity and reproducibility.