| Version | Supported |
|---|---|
latest main |
Yes |
| older tags | No — please upgrade |
Do not open a public GitHub issue for security vulnerabilities.
Report privately via GitHub Security Advisories.
You will need a GitHub account. The advisory is visible only to maintainers until a fix is released.
- Description of the vulnerability
- Steps to reproduce (proof-of-concept if possible)
- Affected component (API, rules engine, training pipeline, Docker image, dependency)
- Potential impact
- Your suggested fix, if any
| Severity | Acknowledgement | Patch target |
|---|---|---|
| CRITICAL / P0 | 48 hours | 14 days |
| HIGH | 72 hours | 30 days |
| MEDIUM / LOW | 5 business days | Next minor release |
In scope:
- Source code in this repository
- Docker image published to
ghcr.io/coderguy-07/railhawk - Dependency vulnerabilities that affect the published image or package
Out of scope:
- Infrastructure not managed in this repository
- Third-party services (UIDAI, NPCI, payment rails)
- Vulnerabilities requiring physical access to deployment hardware
Any vulnerability that could expose raw card numbers (PAN), CVV/CVV2, or full magnetic stripe data is automatically classified as P0 / CRITICAL regardless of CVSS score, and follows the 48h / 14-day SLA above.
We follow coordinated vulnerability disclosure. After a fix is released, we will publish a security advisory crediting the reporter (unless you prefer to remain anonymous).