Skip to content

Security: defi0x1/token-swap-program

Security

SECURITY.md

Security Policy

Status of this code

This program is example and educational code for building an Anchor-based SPL token swap on Solana. It has not been audited by a third party. Do not deploy it to mainnet with real funds, and do not fork it into a production system without an independent security review first.

Reporting a vulnerability

If you find a security issue in this program (for example, a way to drain a pool's vaults outside of withdraw_native_instruction / withdraw_token_instruction, or to bypass the authority / master_authority checks), please report it privately rather than opening a public issue:

  1. Go to the repository's Security tab on GitHub.
  2. Click Report a vulnerability to open a private GitHub Security Advisory.
  3. Describe the issue, the affected instruction(s) or account(s), and, if possible, steps or a test case that reproduces it.

You should get an initial response within a few days. Please give the maintainer a reasonable amount of time to address the report before any public disclosure.

Non-sensitive bugs (build failures, incorrect documentation, test flakiness) can go through a normal GitHub issue instead.

There aren't any published security advisories