Skip to content

docs: expand SECURITY.md with disclosure policy and audit references#1031

Open
IAM-CW wants to merge 1 commit intoUniswap:mainfrom
IAM-CW:docs/expand-security-policy
Open

docs: expand SECURITY.md with disclosure policy and audit references#1031
IAM-CW wants to merge 1 commit intoUniswap:mainfrom
IAM-CW:docs/expand-security-policy

Conversation

@IAM-CW
Copy link
Copy Markdown

@IAM-CW IAM-CW commented Mar 23, 2026

Related Issue

There are no existing issues. The current SECURITY.md was created in response to an OpenZeppelin audit recommendation (PR #774), but it contains only a bug bounty link and an email address. For a protocol with billions in TVL and a $15.5M bug bounty, this file should provide comprehensive security guidance.

Description of changes

This now expands SECURITY.md from a minimal placeholder into a complete security policy.

Added:

  • Vulnerability reporting instructions with what to include
  • Response timeline table (24hr acknowledgment through 90-day disclosure)
  • Bug bounty program summary referencing the $15.5M program
  • Audit table linking to the OpenZeppelin report
  • Supported versions table covering v1 through v4
  • Additional resources section

Preserved:

All content is sourced from publicly available information on uniswap.org and the OpenZeppelin audit report.

@IAM-CW IAM-CW requested a review from a team as a code owner March 23, 2026 11:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant