Security fixes are made against the latest published StarNet release and the current default branch. Older versions may be asked to update before a fix can be applied.
Please do not open a public issue, discussion, or pull request for a suspected vulnerability. Use one of these private channels:
- GitHub's Report a vulnerability button on the repository Security tab, when available.
- Email androo.agi@gmail.com with the subject
StarNet security report.
Include the affected version or commit, reproduction steps, impact, and any suggested mitigation. Remove real credentials and personal data from screenshots, logs, and proof-of-concept files.
You should receive an acknowledgement within three business days. We will investigate, coordinate remediation and disclosure with you, and credit you unless you prefer to remain anonymous.
Reports about secret handling, filesystem or network containment, permission/consent bypasses, update verification, cross-user data exposure, and unintended remote access are especially useful. Please test only against systems and data you own or are authorized to use.