Skip to content

Security: humanx123/btcnode-datum-toolkit

Security

SECURITY.md

Security policy

Sensitive data

Never submit private keys, seed phrases, wallet files, RPC passwords, DATUM admin passwords, .cookie files, VHDX images, or complete configuration files in an issue.

The payout address is public information, but publishing it links mining activity to that address. Redact it when privacy matters.

Reporting a vulnerability

Open a GitHub security advisory in the repository instead of a public issue. Include affected version, reproduction steps, and impact. Remove all credentials and wallet information.

Installer trust

Release executables are not code-signed in version 0.1.0. Compare the downloaded file's SHA-256 hash with the release notes. The installer verifies the pinned Bitcoin Knots archive before extraction and obtains DATUM source from its official GitHub repository.

There aren't any published security advisories