This SDK is developed with the help of AI coding assistants alongside human maintainers, and may still contain bugs, edge cases, or incomplete coverage.
Scallop interactions can create real on-chain transactions. The on-chain protocol state and executed transaction effects are the source of truth. Review transaction inputs carefully, test with small amounts first, and use this SDK at your own risk.
The Scallop Python SDK is still evolving quickly. We currently provide security updates for the latest public release line and the default branch.
| Version | Supported |
|---|---|
0.3.x |
Yes |
master |
Yes |
< 0.3.0 |
No |
Please do not open a public GitHub issue for suspected vulnerabilities.
Instead, email bug@scallop.io with:
- a clear description of the issue
- affected package version or commit
- impact assessment
- reproduction steps or proof of concept, if available
Use the subject line Security Report: sui-scallop-sdk-python.
We aim to:
- acknowledge receipt within 3 business days
- provide an initial triage update within 7 business days
- coordinate remediation and disclosure once a fix is ready
If the report is accepted, we may ask for extra validation details while the fix is being prepared. We appreciate responsible disclosure and will work with reporters to coordinate publication timing.