diff --git a/.github/workflows/repo-integrity-guard.yml b/.github/workflows/repo-integrity-guard.yml index b0fc5733..d10f2246 100644 --- a/.github/workflows/repo-integrity-guard.yml +++ b/.github/workflows/repo-integrity-guard.yml @@ -63,6 +63,21 @@ jobs: done exit $status + - name: Source files must not be patch fragments + run: | + set -euo pipefail + status=0 + while IFS= read -r -d '' file; do + first_content=$(sed -n '/[^[:space:]]/{p;q;}' "$file") + case "$first_content" in + '@@ '*|'*** Begin Patch'*|'diff --git '*) + echo "::error file=${file}::Source file begins with patch syntax: ${first_content}" + status=1 + ;; + esac + done < <(git ls-files -z -- '*.rs' '*.ex' '*.exs' '*.res' '*.js' '*.ts' '*.py' '*.sh') + exit "$status" + - name: Mass-deletion tripwire env: EVENT: ${{ github.event_name }} diff --git a/.gitignore b/.gitignore index 2c1f4a41..ab5733ef 100644 --- a/.gitignore +++ b/.gitignore @@ -15,6 +15,7 @@ # IDE .idea/ .vscode/ +.claude/worktrees/ *.swp *.swo *~ diff --git a/SECURITY.md b/SECURITY.md index 3a101396..af80df73 100644 --- a/SECURITY.md +++ b/SECURITY.md @@ -1,21 +1,36 @@ -# Security Policy +# Security policy -## Supported versions +## Reporting a vulnerability -The `main` branch is the supported version of this project. +Please report suspected vulnerabilities privately through +[GitHub private vulnerability reporting](https://github.com/hyperpolymath/gitbot-fleet/security/advisories/new). +Do not disclose a vulnerability in a public issue, pull request, discussion, or +social-media post before a coordinated fix is available. -## Reporting a vulnerability +Include the affected component and revision, the expected impact, reproduction +steps, and a minimal proof of concept where possible. Please avoid accessing, +modifying, or deleting data beyond what is necessary to demonstrate the issue, +and do not perform denial-of-service testing. + +We aim to acknowledge a report within 48 hours, provide an initial assessment +within seven days, and send status updates at least weekly while remediation is +in progress. Disclosure timing will be coordinated with the reporter; the +default target is within 90 days of the initial report. + +## Supported versions + +Security fixes are made on the default branch. Tagged releases are supported +only when explicitly identified as maintained in their release notes. -Please report security vulnerabilities through GitHub's private vulnerability -reporting feature: +## Safe harbour -1. Open the repository's **Security** tab. -2. Select **Report a vulnerability**. -3. Provide enough detail for the maintainers to reproduce and assess the issue. +We will not pursue legal action against researchers who act in good faith, +follow this policy, avoid privacy and service disruption, and allow reasonable +time for remediation before disclosure. -Do not open a public issue for a security vulnerability. +## Security measures The project's detailed security measures and cryptographic standards are documented in [SECURITY.adoc](SECURITY.adoc).