Reclaim ProtocolReclaim ProtocolTrust Center

Supply Chain

Our guarantee

Every critical vulnerability in any of our open-source dependencies is published here the moment Dependabot flags it. Package, advisory, and our patch status. In public.

The threat model

Most modern code is third-party code. A vulnerability in any transitive dependency can become a vulnerability in our verification pipeline. The integrity guarantee depends on every link in that chain holding.

How it’s enforced

GitHub Dependabot scans every one of our active repos daily against the GitHub Advisory Database. Critical-severity advisories surface to this page automatically; lower severities are triaged internally on a rolling basis.

How you verify

The live table below lists every open critical advisory across every active repo, linked directly to its GHSA entry on GitHub. The full report, including lower-severity issues, is available under NDA.

What you still trust

The GitHub Advisory Database's coverage, and the open-source maintainers we depend on. We pin versions and react to advisories as they appear, but we cannot prevent supply-chain attacks at their source.
Last checked: 22h ago
reclaim-js-sdkreclaim-logs-backendreclaim-inapp-sdkpopcornreclaim-portalattestor-corereclaim-sdk-backendreclaim-devtool-backendreclaim-teereclaim-tee-operator-flutter
JunJulAug
Monitoring started · May 31Aug 28

Today · Aug 28

For any incidents, please report at support@reclaimprotocol.org. Response time: 4 hours for critical, 48 hours for other issues.

© 2026 Reclaim Protocol · trust.reclaimprotocol.org

DocumentationContact

Checks run daily · 90 daily runs on record.

Needs attention

Last checked: 8/27/2026

Critical vulnerabilities found — we’re working on addressing them.

Last checked: 22h ago

Repositories scanned (10)

  • attestor-core
  • popcorn
  • reclaim-devtool-backend
  • reclaim-inapp-sdk
  • reclaim-js-sdk
  • reclaim-logs-backend
  • reclaim-portal
  • reclaim-sdk-backend
  • reclaim-tee
  • reclaim-tee-operator-flutter

Methodology

Checks all repositories for known dependency vulnerabilities via Dependabot alerts.