Skip to content

Security: Lilly-Protocol/lily-sdk

Security

SECURITY.md

Security Policy

Supported Versions

Version Supported
0.1.x

Reporting a Vulnerability

Please do NOT report security vulnerabilities through public GitHub issues.

If you discover a security vulnerability in this project, please report it using one of the following methods:

  • GitHub Security Advisories: Use the "Report a vulnerability" button on the Security tab of this repository.
  • Email: Send details to security@lilyprotocol.com (encrypted with our PGP key if possible).

What to Include

  • Description of the vulnerability
  • Steps to reproduce or proof-of-concept
  • Potential impact assessment
  • Suggested fix (if any)

Response Timeline

  • Acknowledgment: We will acknowledge receipt within 48 hours.
  • Initial Assessment: A preliminary assessment will be provided within 5 business days.
  • Resolution Target: Critical vulnerabilities will be patched within 30 days; lower-severity issues may take longer depending on complexity.

Safe Harbor

We consider security research conducted in accordance with this policy to be:

  • Authorized and lawful
  • Helpful to the overall security of the ecosystem
  • Conducted in good faith

We will not pursue legal action against researchers who follow this policy and act responsibly.

Disclosure Policy

We follow coordinated disclosure. Please allow us reasonable time to address the issue before any public disclosure. We will credit reporters in release notes unless anonymity is requested.

Scope

This policy applies to:

  • The @lily-protocol/sdk npm package
  • Source code in this repository
  • Official documentation and examples

Out of scope: third-party dependencies (report to their maintainers), social engineering attacks, and denial-of-service testing against production systems.

There aren't any published security advisories