Skip to content

Security: mulgadc/northstar

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

Please do not open a public issue for a security vulnerability.

Report it privately, either way works:

Please include enough for us to reproduce it: the version or commit, the configuration involved, and the steps that trigger it. If you have a proof of concept, include that too.

What Happens Next

We aim to acknowledge a report within three business days. We will confirm whether we can reproduce it, agree a fix and a disclosure timeline with you, and credit you in the advisory unless you would rather we did not.

Scope

Northstar is one part of the Mulga stack. If a vulnerability spans more than one component, report it once against whichever repository you found it in and we will handle the rest.

Supported Versions

Fixes land on the latest release and on main. Older releases are not patched.

There aren't any published security advisories