We release security patches for the following versions:
| Version | Supported |
|---|---|
| 3.1.x | ✅ |
| < 3.1 | ❌ |
We take security vulnerabilities seriously. If you discover a security issue, please report it responsibly.
- Do NOT open a public GitHub issue for security vulnerabilities
- Preferred: Use GitHub Security Advisories to report privately through GitHub
- Alternative: Email security concerns to: security@rocketride.ai
- Include as much detail as possible:
- Description of the vulnerability
- Steps to reproduce
- Potential impact
- Suggested fix (if any)
- Acknowledgment: Within 48 hours
- Initial Assessment: Within 5 business days
- Resolution Timeline: Depends on severity
- Critical: 1-7 days
- High: 7-30 days
- Medium: 30-90 days
- Low: Next release cycle
- We will coordinate disclosure with you
- We request a 90-day disclosure window for non-critical issues
- We will credit reporters (unless anonymity is requested)
When using RocketRide Engine:
- Keep Updated: Always use the latest version
- Credentials: Never commit credentials or secrets
- Dependencies: Regularly update dependencies
- Access Control: Implement proper access controls
- Encryption: Use encryption for sensitive data
RocketRide Engine includes several security features:
- Encryption: Support for data encryption at rest and in transit
- Authentication: Configurable authentication mechanisms
- Keystore: Secure key management
- Audit Logging: Comprehensive activity logging
Thank you for helping keep RocketRide Engine secure!