Hummingbird

Security & Contact

Hummingbird's repository is public and its current deployed site remains static, with no public accounts, submission forms, or production application database. The realistic attack surface is concentrated in the source/deployment pipeline today and will expand deliberately when Phase 2 persistence is introduced.

main is protected with required CI, repository Actions are restricted and SHA-pinned, and workflow permissions are read-only. The remaining public-repository security settings are being verified before Phase 1 is declared complete.

A dedicated private vulnerability-reporting path has not yet been verified. Until it is, do not open a public issue containing vulnerability details. Verifying GitHub private vulnerability reporting is a blocker for completing Phase 1.

The repository's SECURITY.md is the authoritative source for the current threat model, controls, retention rules, and unresolved security questions.