Skip to content

Security: astrid-runtime/station

Security

SECURITY.md

Security policy

Astrid Station is a content repository and trust boundary. Reports may include malformed publication records, event-chain or namespace authorization issues, unsafe repository paths, trust metadata rollback/freeze, workflow permission errors, or accidental key/secret exposure.

Reporting a vulnerability

Do not open a public issue for a security vulnerability. Use the private security advisory channel for the eventual repository owner:

https://github.com/astrid-runtime/station/security/advisories/new

The URL is intentionally a placeholder until the repository is provisioned; do not enable public deployment or publish a root key while it remains. Include a concise description, reproduction or fixture, affected commit/path, impact, and any safe mitigation. Never include private keys or credentials in the report.

In scope

  • Acceptance of a malformed or equivocal station_id/coordinate record.
  • Event-envelope digest, sequence, prior-chain, actor, or authorization bypass.
  • Namespace ownership or reserved-authority bypass.
  • TUF root, role, expiry, rollback, or target-integrity failures.
  • Pages workflow signing/deployment occurring without the required checks.
  • Private key, role key, secret, or credential leakage.

Out of scope

  • Availability issues in GitHub Pages or upstream dependencies without a Station-specific impact.
  • Local operator policy choices that correctly deny a publication.

Until the offline ceremony and protected environments exist, this scaffold is not an authoritative production Station and must not be used as one.

There aren't any published security advisories