Skip to content

Security: Nanle-code/StarForge

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

If you discover a security vulnerability in StarForge, please open a GitHub issue or contact the maintainers directly rather than disclosing it publicly, so a fix can be prepared before details are shared widely.

Secrets & PII handling

For a full inventory of where secrets (private keys, API tokens, auth credentials) and PII/metadata (local paths, usernames, IP addresses, AI prompt text) can flow within the CLI — config files, logs, telemetry payloads, AI prompt requests, and stdout/stderr — along with the controls applied at each point and known gaps, see docs/DATA_FLOW_INVENTORY.md.

Related documentation

There aren't any published security advisories