Skip to content

Security: ChiefGyk3D/Stream-Daemon

SECURITY.md

Security policy

Reporting a vulnerability

Please report vulnerabilities privately through GitHub's private vulnerability reporting: https://github.com/ChiefGyk3D/Stream-Daemon/security/advisories/new. Do not open a public issue for a security problem.

You will get an acknowledgement within a few days. Fixes ship as a new release; the advisory is published once the fix is available.

Supported versions

The latest release is supported. Older releases receive no security fixes; upgrade to the current one.

Verifying what you run

Every release is built by the shared workflows in ChiefGyk3D/git-your-ship-together, which sign the container image with cosign (keyless, Sigstore), attach an SPDX SBOM generated by syft as a cosign attestation, and record SLSA build provenance as a GitHub Artifact Attestation. The signing identity is the release workflow itself.

# Signature
cosign verify ghcr.io/chiefgyk3d/stream-daemon:<tag> \
  --certificate-identity-regexp '^https://github.com/ChiefGyk3D/git-your-ship-together/' \
  --certificate-oidc-issuer https://token.actions.githubusercontent.com

# SBOM
cosign verify-attestation --type spdxjson ghcr.io/chiefgyk3d/stream-daemon:<tag> \
  --certificate-identity-regexp '^https://github.com/ChiefGyk3D/git-your-ship-together/' \
  --certificate-oidc-issuer https://token.actions.githubusercontent.com \
  | jq -r .payload | base64 -d | jq .predicate

# Build provenance
gh attestation verify oci://ghcr.io/chiefgyk3d/stream-daemon:<tag> --owner ChiefGyk3D

The same image is published to Docker Hub as docker.io/<dockerhub-user>/stream-daemon with the same signature and attestations.

What the pipeline checks

On every pull request: CodeQL, gitleaks over the full history, pip-audit over the pinned dependencies, dependency review, a Trivy scan of the built image, and actionlint plus zizmor over the workflow files. Dependency updates arrive through Dependabot with a seven-day cooldown on new releases.

Secrets

No credential is stored in this repository or in its GitHub Actions secrets. CI reads what it needs from Doppler over a short-lived OIDC token. If you find something that looks like a credential in this repository's history, report it as above; the documented placeholders are listed in .gitleaks.toml.

There aren't any published security advisories