Skip to content

Security: goncalompontes/rail

Security

SECURITY.md

Security Policy

Supported Versions

Rail is currently in pre-release development (v0.0.0). Only the latest commit on the main branch is supported.

Reporting a Vulnerability

To report a security vulnerability, please use GitHub's private vulnerability reporting feature.

You can expect:

  • Acknowledgment within 48 hours
  • Initial assessment within 5 business days
  • Fix timeline communicated after assessment

Critical vulnerabilities will be prioritized and fixed within 14 days.

Scope

Security issues include:

  • Compiler crashes on valid input (denial of service)
  • Memory safety issues in generated EXRAIL output
  • Unsoundness in the type system or name resolution
  • Malicious input that causes arbitrary code execution during compilation

Bug Bounty

This is a student project and does not offer a bug bounty program.

There aren't any published security advisories