Please report suspected vulnerabilities privately by emailing security@starhaven.io or using GitHub's private vulnerability reporting flow from the affected repository's Security tab. Do not open a public issue for an undisclosed vulnerability.
Useful reports include:
- The affected repository, version, tag, or commit.
- A concise description of the impact.
- Reproduction steps or proof-of-concept details.
- Any suggested mitigation or fix.
- Whether the issue is already public or under embargo.
We will acknowledge the report, investigate it, and coordinate disclosure with you. Fixes are published through advisories, releases, or release notes when appropriate.
Security reports are accepted for actively maintained public repositories in the
starhaven-io organization. Archived repositories and experimental branches are
handled on a best-effort basis.