Hummingbird

Security & Contact

Hummingbird's repository is public and Phase 2 — Read-Only Commons is in progress. There are still no public participant accounts or Hummingbird-owned submission forms; the interim Seed Bank uses public GitHub issues while the first application persistence layer is introduced deliberately.

main is protected with required CI and admin/steward enforcement. Repository Actions are restricted and SHA-pinned. Secret scanning, push protection, Dependabot security controls, and CodeQL default setup are enabled.

Do not open a public issue containing vulnerability details. GitHub private vulnerability reporting is enabled for this repository. Use the repository's Security → Report a vulnerability flow to send a private report to the maintainer.

The repository's SECURITY.md is the authoritative source for the current threat model, controls, retention rules, and security guidance. Public security-related architectural decisions that are safe to disclose are indexed in the Decision Record.