Skip to content

feat: map Safe Harbor whitehat rescue onto the Security Map - #641

Merged
mattaereal merged 1 commit into
feat/security-map-privacyfrom
feat/security-map-safe-harbor
Sep 14, 2026
Merged

mattaereal merged 1 commit into
feat/security-map-privacyfrom
feat/security-map-safe-harbor

Conversation

@mattaereal

Copy link
Copy Markdown
Collaborator

What does this PR change?

Stacked on #640 (Privacy), which stacks on #639 / #638 / #637 / #636 / #635 / #633.

Maps Safe Harbor for the live-exploit window. Independent whitehats freeze without pre-authorization. Adoption and a published recovery address are the controls. Fund return to that address, with SEAL 911, is the response.

Safe Harbor is not a bug bounty and does not replace pause, review, or responsible disclosure.

Unmapped on purpose: eligibility checklist, on-chain registration walkthrough. No Nomad incident node.

Cross-links:

  • Incident Management via the existing smart-contract exploit response
  • Smart contracts and user funds via the active-exploit window
  • Protocol multisig as the recovery destination
  • Governance module via the DAO adoption path

Wallet Security and Vulnerability Disclosure stay unshared until recovery-address hardening and security-contact pages are mapped in those frameworks.

No related-to edges. No incident nodes.

Type of change

  • New content
  • Edit to existing content
  • Outline / structure change
  • Typo or formatting fix
  • Tooling / config

If applicable

  • Editing existing content: tagged the current contributors from the attribution list
  • Framework has a steward: asked them to review
  • Outline change: updated vocs.config.ts with the dev: true parameter
  • Want community feedback: shared this PR in our Discord

Seed adoption, published recovery address, and whitehat fund return.
Not a bug bounty and not a substitute for pause or review. Eligibility
checklist and on-chain registration walkthrough stay unmapped. No Nomad
incident node. Cross-links to Incident Management, smart contracts, the
protocol multisig, and governance come from shared exploit and recovery
nodes.
@cloudflare-workers-and-pages

Copy link
Copy Markdown

Deploying frameworks with  Cloudflare Pages  Cloudflare Pages

Latest commit: 9f02789
Status: ✅  Deploy successful!
Preview URL: https://5e30059f.frameworks-573.pages.dev
Branch Preview URL: https://feat-security-map-safe-harbo.frameworks-573.pages.dev

View logs

@mattaereal
mattaereal added this pull request to stack #643 September 14, 2026 17:24
@mattaereal
mattaereal merged commit 29df337 into develop Sep 14, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant