安全和負責任的披露

Stella Ops Suite 專為可驗證的發行治理而設計:

  • 發行版本為CosignSigstore專案的容器簽章工具,用於簽署和驗證容器映像和製品簽名
  • 證據出口為DSSEDead Simple Signing Envelope - 用於以加密簽章簽署任意資料的簡單靈活標準-證明
  • 政策與決策可以以確定性方式重播以供稽核

供應商安全審查

正在進行供應商盡職調查?審查頁彙整了公開的驗證產物與文件,並列出尚未發布的內容。

報告漏洞

電子郵件: security@stella-ops.org

PGP: 4976 7614 4BBA 5DDB E2EA B5B8 5C1E CABB C9F3 1EA6

That fingerprint belongs to the Stella Ops release-signing key — its user ID is Stella Ops Release Signing <release@stella-ops.org>. The same key currently signs security correspondence, so a signed message from us verifies against it.

A dedicated security-contact key, separate from release signing, and a published key-rotation policy are planned. Neither exists yet.

請包括:

  • 影響+受影響的元件/版本
  • 複製步驟或PoC
  • 相關記錄/畫面截圖
  • 您的首選披露時間線

我們會在72小時內確認並隨時通知您,直到發行修復程序。

驗證您執行的內容

容器映像與 Offline Kit 產物的驗證指令,以及 Cosign 與 PGP 金鑰,統一維護於 /keys/

服務保障

  • Release Integrity: CosignSigstore專案的容器簽章工具,用於簽署和驗證容器映像和製品 簽名 + DSSEDead Simple Signing Envelope - 用於以加密簽章簽署任意資料的簡單靈活標準 指向精確 Git 標籤的套件
  • 證據鏈: Decision Capsules 有簽名且可重播(見 /evidence/
  • 容器強化:部署強化指南見 Security Hardening Guide
  • 實體隔離平價: Offline Kit(參見 /sovereign/

無強制遙測

Web UI 中沒有分析、追蹤器、像素或第三方 JS。產品遙測預設情況下處於禁用狀態,並且嚴格選擇加入。

隱私詳細資訊:/privacy/