This program is example and educational code for building an Anchor-based SPL token swap on Solana. It has not been audited by a third party. Do not deploy it to mainnet with real funds, and do not fork it into a production system without an independent security review first.
If you find a security issue in this program (for example, a way to drain a
pool's vaults outside of withdraw_native_instruction /
withdraw_token_instruction, or to bypass the authority /
master_authority checks), please report it privately rather than opening
a public issue:
- Go to the repository's Security tab on GitHub.
- Click Report a vulnerability to open a private GitHub Security Advisory.
- Describe the issue, the affected instruction(s) or account(s), and, if possible, steps or a test case that reproduces it.
You should get an initial response within a few days. Please give the maintainer a reasonable amount of time to address the report before any public disclosure.
Non-sensitive bugs (build failures, incorrect documentation, test flakiness) can go through a normal GitHub issue instead.