If you discover a security issue in the North Star Framework, please report it responsibly. Do not open a public GitHub issue for security vulnerabilities.
Primary contact: DM @NavigatingTruth on Twitter/X
Please include:
- A clear description of the vulnerability
- Which framework file(s) are affected
- Steps to reproduce the issue
- The potential impact as you understand it
- Acknowledgment within 48 hours of report
- Assessment within 7 days — we'll confirm whether it's a valid issue and share next steps
- Resolution timeline communicated once the scope is understood
- Credit given in the CHANGELOG and release notes (unless you prefer to remain anonymous)
The North Star Framework is a development methodology, not a running application. Security issues in this context include:
- Credential exposure patterns — Example code, templates, or instructions that would lead users to commit secrets, API keys, or tokens to version control
- Unsafe permission guidance — Instructions that encourage
dangerously-skip-permissionsor equivalent flags without proper scoping, or that disable security controls without adequate warning - Malicious fetch targets — Any raw GitHub URL or external URL in the framework that has been compromised or redirects to unintended content
- Hook injection vectors — Patterns in the Hooks Architecture that could allow untrusted input to execute arbitrary shell commands
- Supply chain risks — Recommended tools, dependencies, or MCP servers that have known vulnerabilities or have been compromised
- General bugs or typos — use the Bug Report template
- Enhancement requests — use the Enhancement Request template
- Disagreements about best practices or methodology choices
- Issues in third-party tools listed in the Master Build Framework (report those to the tool maintainers directly)
| Version | Supported |
|---|---|
| v6.1 (current) | ✅ Active |
| v6.0 | |
| v5.0 and earlier | ❌ No longer supported |
North Star Framework — Build with intention. Ship with confidence. Created by @NavigatingTruth