Skip to content

Security: AllStarLink/Voter

SECURITY.md

Security Policy

Reporting a vulnerability

Please report security vulnerabilities privately. Do not file them as public issues, pull requests, forum posts, or discussions.

Use GitHub private vulnerability reporting:

https://github.com/AllStarLink/.github/security/advisories/new

Please name the affected AllStarLink repository or component in your report. Maintainers will route it to the right project.

What to include

  • The affected repository, component, and version
  • A description of the vulnerability and its impact
  • Clear steps to reproduce, or a proof of concept
  • Any suggested mitigation, if you have one

AI-assisted reports

Security reports produced with AI assistance are accepted under the same rules as any other report, per ASL003 - AI Use Practice:

  • You must have verified the problem yourself.
  • The report must include a reproducible demonstration or clear evidence.
  • Do not send embargoed security details to third-party AI services.

Reports that lack a reproducible demonstration may be closed without detailed review.

Policy

There aren't any published security advisories