Skip to content

Security: ichwars/RailKeeper

SECURITY.md

Security Policy

Supported Versions

RailKeeper provides security fixes for the latest stable release and the current main branch. Older releases may no longer receive fixes. Update to the latest stable version before reporting an issue that might already be resolved.

Reporting a Vulnerability

Do not disclose suspected vulnerabilities in public GitHub issues, discussions, or pull requests. Use GitHub private vulnerability reporting so the report, reproduction details, and proposed remediation remain private until a fix is ready.

Include the affected version, deployment shape, impact, reproduction steps, and any relevant logs with secrets removed. Maintainers will acknowledge a report as soon as practical, assess severity, coordinate remediation, and agree on disclosure timing with the reporter.

RailKeeper's implemented controls, deployment requirements, and open hardening work are documented in docs/security.md.

There aren't any published security advisories