mirror of
https://github.com/J3vb/OwnCord.git
synced 2026-09-03 03:50:00 +03:00
- gitignore .serena/ and Client/tauri-client/.env; untrack the .env (the KLIPY key it held is treated as burned; rotation + server-side proxy tracked for P3) - CI: verify generated sqlc output (make sqlc-verify) on the ubuntu leg - CHANGELOG: honest reset narrative (v1.1.0-alpha series), remove references to deleted roadmap files - delete stale docs/phase-a-status.md; fix dangling ref in docs/plans/slash-commands.md - add root SECURITY.md (GitHub-surfaced policy; reporting works while the source repo is private) - docs/audit-2026-04-07.md: add maintained finding-closure table Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
1.1 KiB
1.1 KiB
Security Policy
Supported versions
OwnCord is in alpha. Only the latest release receives security fixes. There are no backports.
| Version | Supported |
|---|---|
| Latest release (see OwnCord-releases) | Yes |
| Anything older | No |
Reporting a vulnerability
Do not open a public issue for security bugs.
Report vulnerabilities privately via GitHub Security Advisories on the OwnCord-releases repository ("Report a vulnerability"). This channel works even while the source repository is private.
Please include:
- Affected component (server, desktop client, admin panel, plugin host)
- Reproduction steps or a proof of concept
- The release version (or source snapshot) you tested against
You will get an initial response within 7 days. Coordinated disclosure is appreciated; fixes ship in the next release with credit unless you prefer otherwise.
Hardening documentation
Operator-facing hardening notes live in docs/security.md.