Skip to content

Security: DCCExpress/DCCExpressLite

Security

SECURITY.md

Security Policy

Please do not publish Wi-Fi credentials, device backups, private layouts, locomotive rosters, GitHub tokens, or signing keys in issues or pull requests.

For a security vulnerability, contact the DCCExpress maintainers privately through the organization owner instead of opening a public issue.

Official firmware releases should only be installed when their SHA-256 hashes match the signed GitHub Release manifest.

There aren't any published security advisories