Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
15 changes: 15 additions & 0 deletions .github/workflows/repo-integrity-guard.yml
Original file line number Diff line number Diff line change
Expand Up @@ -63,6 +63,21 @@ jobs:
done
exit $status

- name: Source files must not be patch fragments
run: |
set -euo pipefail
status=0
while IFS= read -r -d '' file; do
first_content=$(sed -n '/[^[:space:]]/{p;q;}' "$file")
case "$first_content" in
'@@ '*|'*** Begin Patch'*|'diff --git '*)
echo "::error file=${file}::Source file begins with patch syntax: ${first_content}"
status=1
;;
esac
done < <(git ls-files -z -- '*.rs' '*.ex' '*.exs' '*.res' '*.js' '*.ts' '*.py' '*.sh')
exit "$status"

- name: Mass-deletion tripwire
env:
EVENT: ${{ github.event_name }}
Expand Down
1 change: 1 addition & 0 deletions .gitignore
Original file line number Diff line number Diff line change
Expand Up @@ -15,6 +15,7 @@
# IDE
.idea/
.vscode/
.claude/worktrees/
*.swp
*.swo
*~
Expand Down
35 changes: 25 additions & 10 deletions SECURITY.md
Original file line number Diff line number Diff line change
@@ -1,21 +1,36 @@
<!-- SPDX-License-Identifier: MPL-2.0 -->

# Security Policy
# Security policy

## Supported versions
## Reporting a vulnerability

The `main` branch is the supported version of this project.
Please report suspected vulnerabilities privately through
[GitHub private vulnerability reporting](https://github.com/hyperpolymath/gitbot-fleet/security/advisories/new).
Do not disclose a vulnerability in a public issue, pull request, discussion, or
social-media post before a coordinated fix is available.

## Reporting a vulnerability
Include the affected component and revision, the expected impact, reproduction
steps, and a minimal proof of concept where possible. Please avoid accessing,
modifying, or deleting data beyond what is necessary to demonstrate the issue,
and do not perform denial-of-service testing.

We aim to acknowledge a report within 48 hours, provide an initial assessment
within seven days, and send status updates at least weekly while remediation is
in progress. Disclosure timing will be coordinated with the reporter; the
default target is within 90 days of the initial report.

## Supported versions

Security fixes are made on the default branch. Tagged releases are supported
only when explicitly identified as maintained in their release notes.

Please report security vulnerabilities through GitHub's private vulnerability
reporting feature:
## Safe harbour

1. Open the repository's **Security** tab.
2. Select **Report a vulnerability**.
3. Provide enough detail for the maintainers to reproduce and assess the issue.
We will not pursue legal action against researchers who act in good faith,
follow this policy, avoid privacy and service disruption, and allow reasonable
time for remediation before disclosure.

Do not open a public issue for a security vulnerability.
## Security measures

The project's detailed security measures and cryptographic standards are
documented in [SECURITY.adoc](SECURITY.adoc).
Loading