Astrid Station is a content repository and trust boundary. Reports may include malformed publication records, event-chain or namespace authorization issues, unsafe repository paths, trust metadata rollback/freeze, workflow permission errors, or accidental key/secret exposure.
Do not open a public issue for a security vulnerability. Use the private security advisory channel for the eventual repository owner:
https://github.com/astrid-runtime/station/security/advisories/new
The URL is intentionally a placeholder until the repository is provisioned; do not enable public deployment or publish a root key while it remains. Include a concise description, reproduction or fixture, affected commit/path, impact, and any safe mitigation. Never include private keys or credentials in the report.
- Acceptance of a malformed or equivocal
station_id/coordinate record. - Event-envelope digest, sequence, prior-chain, actor, or authorization bypass.
- Namespace ownership or reserved-authority bypass.
- TUF root, role, expiry, rollback, or target-integrity failures.
- Pages workflow signing/deployment occurring without the required checks.
- Private key, role key, secret, or credential leakage.
- Availability issues in GitHub Pages or upstream dependencies without a Station-specific impact.
- Local operator policy choices that correctly deny a publication.
Until the offline ceremony and protected environments exist, this scaffold is not an authoritative production Station and must not be used as one.