Files
OwnCord/SECURITY.md
T
J3vbandClaude Opus 5 9a0ae0dd2a feat(release): fold distribution back into the source repo
The separate J3vb/OwnCord-releases repo existed only because this repo was
private: it carried the AGPL source snapshot and provided a publicly-readable
update feed. Once this repo is public both roles collapse into its own Releases
page, so the mirror is pure redundancy.

- Server/config/config.go: github.repo default OwnCord-releases -> OwnCord.
  This one default drives both the server self-update and the client
  auto-update chain (tauri.conf.json updater.endpoints is empty, so the client
  resolves through the server). No test pinned the old value.
- release.yml: drop the mirror step and its RELEASES_REPO_TOKEN guard, whose
  AGPL/private-repo premise no longer holds. The existing Create GitHub Release
  step is now the sole publish target. All 31 SHA pins verified intact.
- Repoint the README badge/download link, both SECURITY.md links, the
  server-configuration table and sample, the system-overview diagram node and
  the CHANGELOG note. SECURITY.md's advisory link is the load-bearing one: left
  alone it would 404 once the mirror repo is deleted.
- README: Go 1.25+ -> 1.26+ (badge and prerequisite) to match the toolchain
  actually required.

Deleting the mirror repo loses nothing: both repos' v1.1.0-alpha.2 carry
byte-identical asset sets, signatures and update manifest included.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-07-30 16:05:01 +02:00

1.1 KiB

Security Policy

Supported versions

OwnCord is in alpha. Only the latest release receives security fixes. There are no backports.

Version Supported
Latest release (see Releases) Yes
Anything older No

Reporting a vulnerability

Do not open a public issue for security bugs.

Report vulnerabilities privately via GitHub Security Advisories on the OwnCord repository ("Report a vulnerability"). Advisories stay private until published, so this channel is safe even though the repository is public.

Please include:

  • Affected component (server, desktop client, admin panel, plugin host)
  • Reproduction steps or a proof of concept
  • The release version (or source snapshot) you tested against

You will get an initial response within 7 days. Coordinated disclosure is appreciated; fixes ship in the next release with credit unless you prefer otherwise.

Hardening documentation

Operator-facing hardening notes live in docs/security.md.