Skip to content

Security: rstreamlabs/rstream-java

SECURITY.md

Security Policy

If you believe you have found a security issue in rstream-java, please avoid opening a public issue with exploit details.

Use GitHub private vulnerability reporting for this repository when it is available. If that path is not enabled yet, contact the maintainers privately at reports@rstream.io before disclosing the issue in public.

When reporting an issue, include:

  • the affected package or SDK surface
  • the version or commit you tested
  • the operating system and Java version
  • the impact you observed
  • enough reproduction detail for the issue to be validated

Do not include real authentication tokens, webhook signing secrets, private keys, customer endpoint URLs, or customer payloads in public reports.

Security reports are treated as a priority and handled through a coordinated fix and disclosure process.

There aren't any published security advisories