That fingerprint belongs to the Stella Ops release-signing key — its user ID is Stella Ops Release Signing <release@stella-ops.org>. The same key currently signs security correspondence, so a signed message from us verifies against it.
A dedicated security-contact key, separate from release signing, and a published key-rotation policy are planned. Neither exists yet.
Please include:
Impact + affected component/version
Reproduction steps or PoC
Relevant logs/screenshots
Your preferred disclosure timeline
We acknowledge within 72 hours and keep you informed until a fix is published.
Verify what you run
Verification commands for container images and Offline Kit artifacts, together with the Cosign and PGP keys, are maintained at /keys/.
Safeguards in service
Release integrity:Cosign?Container signing tool from Sigstore project for signing and verifying container images and artifacts signatures + DSSE?Dead Simple Signing Envelope - a simple, flexible standard for signing arbitrary data with cryptographic signatures bundles referencing the exact Git tag
Evidence chain: Decision Capsules are signed and replayable (see /evidence/)