Please report vulnerabilities privately through GitHub's private vulnerability reporting: https://github.com/ChiefGyk3D/Stream-Daemon/security/advisories/new. Do not open a public issue for a security problem.
You will get an acknowledgement within a few days. Fixes ship as a new release; the advisory is published once the fix is available.
The latest release is supported. Older releases receive no security fixes; upgrade to the current one.
Every release is built by the shared workflows in ChiefGyk3D/git-your-ship-together, which sign the container image with cosign (keyless, Sigstore), attach an SPDX SBOM generated by syft as a cosign attestation, and record SLSA build provenance as a GitHub Artifact Attestation. The signing identity is the release workflow itself.
# Signature
cosign verify ghcr.io/chiefgyk3d/stream-daemon:<tag> \
--certificate-identity-regexp '^https://github.com/ChiefGyk3D/git-your-ship-together/' \
--certificate-oidc-issuer https://token.actions.githubusercontent.com
# SBOM
cosign verify-attestation --type spdxjson ghcr.io/chiefgyk3d/stream-daemon:<tag> \
--certificate-identity-regexp '^https://github.com/ChiefGyk3D/git-your-ship-together/' \
--certificate-oidc-issuer https://token.actions.githubusercontent.com \
| jq -r .payload | base64 -d | jq .predicate
# Build provenance
gh attestation verify oci://ghcr.io/chiefgyk3d/stream-daemon:<tag> --owner ChiefGyk3DThe same image is published to Docker Hub as docker.io/<dockerhub-user>/stream-daemon with the same signature and attestations.
On every pull request: CodeQL, gitleaks over the full history, pip-audit over the pinned dependencies, dependency review, a Trivy scan of the built image, and actionlint plus zizmor over the workflow files. Dependency updates arrive through Dependabot with a seven-day cooldown on new releases.
No credential is stored in this repository or in its GitHub Actions secrets.
CI reads what it needs from Doppler over a short-lived OIDC token. If you find
something that looks like a credential in this repository's history, report it
as above; the documented placeholders are listed in .gitleaks.toml.