From 4287cd429d2aa54227d989cf4071b9d8d6196bf3 Mon Sep 17 00:00:00 2001 From: cupcakearmy Date: Sat, 10 Sep 2022 13:13:09 +0200 Subject: [PATCH 1/2] security reporting --- README.md | 4 ++++ SECURITY.md | 18 ++++++++++++++++++ 2 files changed, 22 insertions(+) create mode 100644 SECURITY.md diff --git a/README.md b/README.md index ea8ccaf..b390078 100644 --- a/README.md +++ b/README.md @@ -155,6 +155,10 @@ pnpm run ci:server pnpm run test:local ``` +## Security + +Please refer to the security section [here](./SECURITY.md). + ###### Attributions - Test data: diff --git a/SECURITY.md b/SECURITY.md new file mode 100644 index 0000000..703f870 --- /dev/null +++ b/SECURITY.md @@ -0,0 +1,18 @@ +# Security Policy + +## Supported Versions + +Please ensure that you are using the latest major version available. + +| Version | Supported | +| ------- | --------- | +| 2.x | ✅ | +| < 1.x | ❌ | + +## Reporting a vulnerability + +_cryptgeon_ has a full disclosure vulnerability policy. +Report any bug / vulnerability directly to the [issue tracker](https://github.com/cupcakearmy/cryptgeon/issues). +Please do NOT attempt to report any security vulnerability in this code privately to anybody. + +> Shamefully copied of the [ring security section](https://github.com/briansmith/ring#bug-reporting). From 2d573edcacab62ae4370bcd0016132771baca4ad Mon Sep 17 00:00:00 2001 From: cupcakearmy Date: Mon, 12 Sep 2022 14:24:05 +0200 Subject: [PATCH 2/2] change link --- README.md | 2 +- README_zh-CN.md | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/README.md b/README.md index b390078..dea4a73 100644 --- a/README.md +++ b/README.md @@ -26,7 +26,7 @@ _cryptgeon_ is a secure, open source sharing note or file service inspired by [_ ## Demo -Check out the demo and see for yourself https://cryptgeon.nicco.io. +Check out the demo and see for yourself [cryptgeon.org](https://cryptgeon.org) ## Features diff --git a/README_zh-CN.md b/README_zh-CN.md index 20861b7..2f5ae0d 100644 --- a/README_zh-CN.md +++ b/README_zh-CN.md @@ -26,7 +26,7 @@ _加密鸽_ 是一个受 [_PrivNote_](https://privnote.com)项目启发的安全 ## 演示示例 -查看加密鸽的在线演示 demo: https://cryptgeon.nicco.io. +查看加密鸽的在线演示 demo: [cryptgeon.org](https://cryptgeon.org) ## 功能