This policy covers all repositories in the Ride-The-Lightning GitHub organisation. The
main application, RTL, has a more detailed
policy in its own SECURITY.md
— the reporting channels are the same.
Please do not open a public GitHub issue for a security vulnerability.
- GitHub private vulnerability reporting (preferred): use the Security tab of the repository concerned and choose Report a vulnerability. If that repository does not offer it, report through the RTL repository instead: https://github.com/Ride-The-Lightning/RTL/security/advisories/new.
- Email:
security@ridethelightning.info— start the subject with[RTL-SEC]. You can encrypt to the RTL release-signing key, fingerprint3E9B D443 6C28 8039 CA82 7A92 00C9 E2BC 2E45 666F.
Please say which repository the report concerns. Do not send attachments — paste a proof of concept inline or link a private gist. We acknowledge reports within 72 hours. There is no bug bounty.
- c-lightning-REST is archived and unmaintained (since 24 July 2026) in favour of
Core Lightning's built-in
clnrest. It will not receive fixes; if you are still running it, please migrate. We would still like to hear about serious issues so we can warn remaining users, but there will be no patched release. - RTL-Design, RTL-Web and RTL-Quickpay contain design assets, the project website and a browser extension respectively; they hold no node credentials.
- rtlreviewbot / rtlreviewbot-action are maintainer tooling for pull-request review.
Only the latest release of each project receives security fixes.