Dimes operates on-chain leverage infrastructure. We take vulnerability reports seriously and appreciate the work of security researchers.
Do not report security vulnerabilities through public GitHub issues, discussions, or pull requests.
Instead, use GitHub's private vulnerability reporting on the affected repository: open the Security tab and click Report a vulnerability. This creates a private channel visible only to you and the maintainers.
Please include:
- The repository and version or commit affected
- A description of the issue and its impact
- Steps to reproduce, ideally a minimal proof of concept
- Any suggested mitigation
- We aim to acknowledge reports within 3 business days.
- We will keep you updated as we investigate and confirm the issue.
- We will credit you in the advisory unless you prefer to remain anonymous.
This policy covers the code in this GitHub organization:
dimes-demo-ui is reference software intended as a starting point, not a production deployment.
Findings that depend on it being deployed as-is, without the hardening a production integration
would apply, are generally out of scope.
For vulnerabilities in the Multiply protocol contracts or the Dimes API itself, use the same reporting channel above.
We support the latest released version of @dimes-dot-fi/sdk. Security fixes are not backported to
earlier major versions unless separately agreed.