Skip to content

Security: musefly-ai/sim

Security

SECURITY.md

Security Policy

Reporting a vulnerability

Report privately, not in a public issue. Open a draft security advisory on the affected repository — for the Fruit Fly World app and contracts that is fruitflyworld/fruit-fly-world — or contact a maintainer directly on GitHub.

Please include what you did, what happened, and what you expected. A proof of concept or a reproduction against a deployed address or a live host helps more than a description.

We will acknowledge the report, tell you whether we agree it is a finding, and say what we intend to do. We will credit you in the advisory unless you would rather we did not.

Scope

The Passport is deployed on Ethereum Sepolia, a test network. There is no mainnet deployment. Findings against the testnet contract are still worth reporting — the same source is what would be deployed.

Each repository's own SECURITY.md, where it has one, is more specific than this file and takes precedence.

There aren't any published security advisories