Currently, TransitOps is under active initial development. Security updates are focused on the main trunk branch.
| Version | Supported |
|---|---|
| 0.x.x | ✅ |
| < 0.1.0 | ❌ |
We take the security of TransitOps seriously. If you find a security vulnerability, please do not open a public issue. Instead, report it using the following process:
- GitHub Security Advisory: Please draft a security advisory directly via the GitHub repository's "Security" tab under "Advisories" if you have access.
- Contact Team Lead: You can reach out directly to team members listed in TEAM.md via direct message on the official Slack/Discord/Hackathon coordination channel.
Please provide a detailed summary of the vulnerability, including:
- A description of the issue.
- Steps to reproduce the issue (proof-of-concept script, payloads, or screenshots).
- Potential impact of the vulnerability.
We ask that you follow responsible disclosure principles:
- Give us reasonable time to investigate and mitigate the issue before making it public.
- Do not exploit the vulnerability (e.g., extracting confidential database information, performing denial-of-service, etc.) beyond what is strictly necessary to demonstrate it.
- Keep details of the vulnerability confidential until a patch is released.