Skip to content

Security: SnehalPrince/KisanQueue

Security

SECURITY.md

Security Policy

Supported Versions

We provide security patches and vulnerability updates for the active version of KisanQueue.

Version Supported
1.0.x
< 1.0

Reporting a Vulnerability

The security of farmers' personal data, queue integrity, and gate pass authentication tokens is critical to the KisanQueue mission.

If you discover a security vulnerability or exploit within KisanQueue:

  1. Do NOT disclose the issue publicly in GitHub issues or social media.
  2. Submit a Private Vulnerability Report via GitHub Security Advisories at: https://github.com/SnehalPrince/KisanQueue/security/advisories/new
  3. Include in your report:
    • Detailed description of the vulnerability (e.g. CSRF, QR HMAC forgery, timing attacks, SQL injection)
    • Step-by-step reproduction instructions or Proof-of-Concept (PoC)
    • Potential impact on mandi operations or farmer data privacy

Response Timeline

  • Initial Acknowledgement: Within 24 hours
  • Severity Triage: Within 48 hours
  • Patch & Advisory Release: Coordinated with reporter within 7 days

Thank you for responsibly disclosing vulnerabilities and keeping Indian agriculture digital infrastructure secure.

There aren't any published security advisories