Rail is currently in pre-release development (v0.0.0).
Only the latest commit on the main branch is supported.
To report a security vulnerability, please use GitHub's private vulnerability reporting feature.
You can expect:
- Acknowledgment within 48 hours
- Initial assessment within 5 business days
- Fix timeline communicated after assessment
Critical vulnerabilities will be prioritized and fixed within 14 days.
Security issues include:
- Compiler crashes on valid input (denial of service)
- Memory safety issues in generated EXRAIL output
- Unsoundness in the type system or name resolution
- Malicious input that causes arbitrary code execution during compilation
This is a student project and does not offer a bug bounty program.