Skip to content
This repository was archived by the owner on Jul 24, 2026. It is now read-only.

Security: Ride-The-Lightning/c-lightning-REST

Security

SECURITY.md

Security Policy

This policy covers all repositories in the Ride-The-Lightning GitHub organisation. The main application, RTL, has a more detailed policy in its own SECURITY.md — the reporting channels are the same.

Please do not open a public GitHub issue for a security vulnerability.

Reporting a vulnerability

  • GitHub private vulnerability reporting (preferred): use the Security tab of the repository concerned and choose Report a vulnerability. If that repository does not offer it, report through the RTL repository instead: https://github.com/Ride-The-Lightning/RTL/security/advisories/new.
  • Email: security@ridethelightning.info — start the subject with [RTL-SEC]. You can encrypt to the RTL release-signing key, fingerprint 3E9B D443 6C28 8039 CA82 7A92 00C9 E2BC 2E45 666F.

Please say which repository the report concerns. Do not send attachments — paste a proof of concept inline or link a private gist. We acknowledge reports within 72 hours. There is no bug bounty.

Repository notes

  • c-lightning-REST is archived and unmaintained (since 24 July 2026) in favour of Core Lightning's built-in clnrest. It will not receive fixes; if you are still running it, please migrate. We would still like to hear about serious issues so we can warn remaining users, but there will be no patched release.
  • RTL-Design, RTL-Web and RTL-Quickpay contain design assets, the project website and a browser extension respectively; they hold no node credentials.
  • rtlreviewbot / rtlreviewbot-action are maintainer tooling for pull-request review.

Supported versions

Only the latest release of each project receives security fixes.

There aren't any published security advisories