# Security policy ## Supported versions Security fixes are made against the latest published StarNet release and the current default branch. Older versions may be asked to update before a fix can be applied. ## Reporting a vulnerability Please do not open a public issue, discussion, or pull request for a suspected vulnerability. Use one of these private channels: 1. GitHub's **Report a vulnerability** button on the repository Security tab, when available. 2. Email **androo.agi@gmail.com** with the subject `StarNet security report`. Include the affected version or commit, reproduction steps, impact, and any suggested mitigation. Remove real credentials and personal data from screenshots, logs, and proof-of-concept files. You should receive an acknowledgement within three business days. We will investigate, coordinate remediation and disclosure with you, and credit you unless you prefer to remain anonymous. ## Scope Reports about secret handling, filesystem or network containment, permission/consent bypasses, update verification, cross-user data exposure, and unintended remote access are especially useful. Please test only against systems and data you own or are authorized to use.