Skip to content

Repository files navigation

Cosmos Maintenance and Security

This repository holds the artifacts and references behind maintenance and security of the Cosmos Stack: published advisories, third-party audits, incident communications, the severity classification framework, and the release and maintenance policy.

Vulnerabilities are not reported here. See below.

Reporting a vulnerability

Report through the Cosmos Immunefi Bug Bounty Program. That is the only route eligible for a bounty.

Never open a public issue, pull request, or discussion for a suspected vulnerability.

security@cosmos.network is monitored continuously for security coordination with chains and partners. Reports that arrive there are acted on, but they are not eligible for a bounty.

The full policy, covering how reports are handled, how fixes are distributed, when details are disclosed, and what happens if someone publishes ahead of the disclosure date, is served to every repository in the organization from cosmos/.github/SECURITY.md.

Receiving patches privately

Teams running the Cosmos Stack in production can sign up for private security notifications by filling out this form.

Signing up is the first step, not access itself. Receiving fixes before they are public additionally requires completing KYC, which is arranged by email with security@cosmos.network.

Policies

Policy Where it lives
Vulnerability disclosure and bug bounty cosmos/.github/SECURITY.md
Severity classification resources/CLASSIFICATION_MATRIX.md
Release families, support windows, retirement docs.cosmos.network
Release and maintenance POLICY.md
Code of Conduct cosmos/.github/CODE_OF_CONDUCT.md
Contributing cosmos/.github/CONTRIBUTING.md

The disclosure policy, code of conduct, and contributing guide live in cosmos/.github so that every repository in the organization serves the same copy. They are not duplicated here.

What is in this repository

Path Contents
ADVISORIES.md Every ASA advisory issued to date, linked to its GHSA
audits/ Third-party audit reports, by component
communications/ Incident post mortems, and pre-notifications with their detached signatures
reports/ Transparency reports
resources/ Severity classification framework and liveness guidance
release/ Release signing keys

A note on liveness

The Cosmos Stack is built on safety over liveness and does not offer distributed performance guarantees. resources/LIVENESS.md sets out what that means for anyone building on it.

About

Cosmos Security contains guidelines (and tools in the future) for a responsible security incident disclosure

Resources

Code of conduct

Contributing

Security policy

Stars

12 stars

Watchers

2 watching

Forks

Contributors

Languages