Skip to content

Security: harshit-kumar-dev/TransitOps

Security

SECURITY.md

Security Policy

Supported Versions

Currently, TransitOps is under active initial development. Security updates are focused on the main trunk branch.

Version Supported
0.x.x
< 0.1.0

Reporting a Vulnerability

We take the security of TransitOps seriously. If you find a security vulnerability, please do not open a public issue. Instead, report it using the following process:

  1. GitHub Security Advisory: Please draft a security advisory directly via the GitHub repository's "Security" tab under "Advisories" if you have access.
  2. Contact Team Lead: You can reach out directly to team members listed in TEAM.md via direct message on the official Slack/Discord/Hackathon coordination channel.

What to Include

Please provide a detailed summary of the vulnerability, including:

  • A description of the issue.
  • Steps to reproduce the issue (proof-of-concept script, payloads, or screenshots).
  • Potential impact of the vulnerability.

Responsible Disclosure Expectations

We ask that you follow responsible disclosure principles:

  • Give us reasonable time to investigate and mitigate the issue before making it public.
  • Do not exploit the vulnerability (e.g., extracting confidential database information, performing denial-of-service, etc.) beyond what is strictly necessary to demonstrate it.
  • Keep details of the vulnerability confidential until a patch is released.

There aren't any published security advisories