Please report security vulnerabilities privately. Do not file them as public issues, pull requests, forum posts, or discussions.
Use GitHub private vulnerability reporting:
https://github.com/AllStarLink/.github/security/advisories/new
Please name the affected AllStarLink repository or component in your report. Maintainers will route it to the right project.
- The affected repository, component, and version
- A description of the vulnerability and its impact
- Clear steps to reproduce, or a proof of concept
- Any suggested mitigation, if you have one
Security reports produced with AI assistance are accepted under the same rules as any other report, per ASL003 - AI Use Practice:
- You must have verified the problem yourself.
- The report must include a reproducible demonstration or clear evidence.
- Do not send embargoed security details to third-party AI services.
Reports that lack a reproducible demonstration may be closed without detailed review.