Skip to content

Security: Jul1usCrypto/SolCity

Security

SECURITY.md

Security Policy

Supported Versions

SolCity is actively developed. Security fixes are applied to the latest version on main.

Version Supported
latest (main)
older commits

Reporting a Vulnerability

We take security seriously. If you discover a vulnerability in SolCity, please do not open a public GitHub issue.

How to Report

Please report vulnerabilities by emailing the maintainer directly or using GitHub's private security advisory feature:

  1. Go to the Security Advisories page
  2. Click "Report a vulnerability"
  3. Fill in the details of the issue

Alternatively, you can reach out to the team via X/Twitter.

What to Include

Please include as much of the following information as possible to help us understand and resolve the issue quickly:

  • A description of the vulnerability and its potential impact
  • Steps to reproduce the issue
  • Any proof-of-concept or exploit code (if applicable)
  • Affected component(s) (e.g., auth flow, API route, Supabase RLS policy)

Sensitive Areas

SolCity handles the following sensitive data — please pay special attention when auditing:

  • Helius API keys — used for Solana RPC calls
  • Supabase Row Level Security (RLS) — controls data access per user
  • Stripe payment webhooks — handles payment events
  • API routes — under src/app/api/ — ensure proper authentication checks
  • CRON endpoints — protected by CRON_SECRET; unauthorized access could trigger unintended server actions

Response Timeline

  • Acknowledgement: Within 72 hours of receiving a report
  • Status update: Within 7 days
  • Fix or mitigation: Depends on severity; critical issues will be prioritized

Disclosure Policy

We follow a coordinated disclosure model. Once a fix is available, we will:

  1. Publish a GitHub Security Advisory
  2. Credit the reporter (unless they wish to remain anonymous)
  3. Release a patched version

Thank you for helping keep SolCity and its users safe!

There aren't any published security advisories