If you discover a security vulnerability anywhere in the Matchids ecosystem, please do not open a public issue in any repo. Email the maintainers directly with:
- A description of the vulnerability and which repo it affects
- Steps to reproduce
- Potential impact
Because Matchids serves children and handles payments (including Web3 payments through CeloHT), we treat security reports as high priority and will acknowledge reports as quickly as we can.
This applies to every repository in the Matchids organization:
matchids-web, matchids-backend, matchids-database,
matchids-payments, matchids-celoht, matchids-admin,
matchids-content, matchids-design-system, matchids-infrastructure,
and this repo itself.
We ask that you give us reasonable time to investigate and address a report before any public disclosure, and that you avoid accessing, modifying, or deleting data that isn't yours in the course of testing.