Security fixes are applied to the current main branch and the most recent GitHub release. Older tags are not maintained unless a maintainer explicitly announces an exception.
Do not open a public issue for a suspected vulnerability. Use the repository's private security advisory reporting channel when available, or contact the repository owner privately. Include a minimal reproduction, affected revision, impact assessment, and any proposed mitigation.
We aim to acknowledge reports within 5 business days, provide a status update within 10 business days, and coordinate disclosure after a fix or documented mitigation is available.
This project accepts synthetic railway scenarios and synthetic personnel data only. Never include production operational data, personal data, credentials, tokens, private keys, or internal infrastructure details in issues, pull requests, fixtures, logs, benchmark bundles, or releases. Redact sensitive material before reporting a defect.
Please give maintainers a reasonable opportunity to investigate and remediate a report before public disclosure. We will credit reporters who wish to be credited after coordinated disclosure.