| Version | Supported |
|---|---|
| 2.x | ✅ |
| < 2.0 | ❌ |
If you discover a security vulnerability in rLightning, please report it responsibly.
Do NOT open a public issue for security vulnerabilities.
Instead, please use GitHub Security Advisories to report the vulnerability privately.
You can expect:
- Acknowledgment within 48 hours
- A fix or mitigation plan within 7 days for critical issues
- Credit in the release notes (unless you prefer to remain anonymous)
This policy covers the rLightning server and its official Docker images. It does not cover third-party clients or integrations.