We provide security patches and vulnerability updates for the active version of KisanQueue.
| Version | Supported |
|---|---|
| 1.0.x | ✅ |
| < 1.0 | ❌ |
The security of farmers' personal data, queue integrity, and gate pass authentication tokens is critical to the KisanQueue mission.
If you discover a security vulnerability or exploit within KisanQueue:
- Do NOT disclose the issue publicly in GitHub issues or social media.
- Submit a Private Vulnerability Report via GitHub Security Advisories at:
https://github.com/SnehalPrince/KisanQueue/security/advisories/new - Include in your report:
- Detailed description of the vulnerability (e.g. CSRF, QR HMAC forgery, timing attacks, SQL injection)
- Step-by-step reproduction instructions or Proof-of-Concept (PoC)
- Potential impact on mandi operations or farmer data privacy
- Initial Acknowledgement: Within 24 hours
- Severity Triage: Within 48 hours
- Patch & Advisory Release: Coordinated with reporter within 7 days
Thank you for responsibly disclosing vulnerabilities and keeping Indian agriculture digital infrastructure secure.