Only the current main branch is supported. This repository is a synthetic
reference and is not a hosted service.
Use GitHub private vulnerability reporting when available. Do not open a public issue containing credentials, webhook secrets, customer or payment data, private URLs, proprietary code, or an exploit against a system you do not own or lack authorization to test.
If a report concerns Stripe itself, follow Stripe's official security reporting process. This project is independent and cannot triage provider vulnerabilities.
Run the included deterministic fixtures locally. Do not point this harness at a live endpoint, replay real events, scan third-party systems, or substitute a production signing secret. All fixture values must stay visibly synthetic.