This is the vulnerability disclosure policy for the Panurus project. It conforms to the
LF Decentralized Trust Security Vulnerability Disclosure Policy and is adapted
from the LFDT SAMPLE-SECURITY.md template. Where this document is silent, the LFDT policy governs.
The Panurus security team is responsible for receiving, triaging, and coordinating the response to vulnerability reports. Each member subscribes to the LF Decentralized Trust security email list and to LFDT-wide security infrastructure. Members are added to and removed from the team via approved pull requests against this file.
| Name | Email ID | Discord ID | Area/Specialty |
|---|---|---|---|
| Angelo De Caro | adc@zurich.ibm.com | adecaro | Cryptography, zero-knowledge token protocols (zkatdlog) |
| Kaoutar Elkhiyaoui | kao@zurich.ibm.com | KElkhiyaoui | Cryptography, token protocol design and validation |
| Akram Bitar | akram@il.ibm.com | akrambitar | SDK, drivers, integration and CI |
Because Panurus contains security-sensitive cryptographic code — zero-knowledge proofs, range
proofs, and Idemix-based identity under token/core/zkatdlog/ — the security team includes
maintainers with cryptography expertise, per the LFDT policy.
The security team accepts the following responsibilities:
Vulnerability discussion happens in the private GitHub Security Advisory opened for the report. A private channel on the LF Decentralized Trust Discord may be created if broader coordination is required.
Do not discuss a suspected vulnerability in a public issue, pull request, discussion, or Discord channel before it has been disclosed.
Report a suspected vulnerability through either of these channels:
LFDT-Panurus/panurus),Reports are handled per the response outline above.
GitHub acts as the CVE Numbering Authority (CNA) for Panurus. The security team requests CVE identifiers through the GitHub Security Advisory workflow.
Panurus does not maintain a project-specific embargo list. Where an embargo is warranted, the security team coordinates through the LFDT security email list and the private GitHub advisory. Requests to be included in a specific embargo should be sent to security@lists.lfdecentralizedtrust.org with the project name and the rationale for a need-to-know.
Panurus uses GitHub Security Advisories as its advisory mechanism. Published advisories are the authoritative record of disclosed vulnerabilities for the project.
Panurus uses GitHub’s private vulnerability patching features, which allow the fix to be developed and reviewed in a private fork associated with the advisory. Maintainers needing access or assistance can contact community-architects@lfdecentralizedtrust.org.
This policy borrows heavily from the recommendations of the OpenSSF Vulnerability Disclosure working group (ossf/wg-vulnerability-disclosures), and the response outline derives from the OpenSSF maintainers guide.

This work is licensed under a Creative Commons Attribution 4.0 International License.