Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
26 changes: 26 additions & 0 deletions .github/dependabot.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,26 @@
version: 2

updates:
# Go modules (go.mod / go.sum at the repository root).
- package-ecosystem: gomod
directory: /
schedule:
interval: weekly

# The SvelteKit admin app. pnpm is handled by the npm ecosystem.
- package-ecosystem: npm
directory: /frontend
schedule:
interval: weekly

# Actions pinned in .github/workflows/.
- package-ecosystem: github-actions
directory: /
schedule:
interval: weekly

# Base images in the root Dockerfile.
- package-ecosystem: docker
directory: /
schedule:
interval: weekly
51 changes: 51 additions & 0 deletions SECURITY.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,51 @@
# Security policy

## Supported versions

Calnode is pre-1.0, and fixes go onto the latest release line only. There are no
backports to earlier `0.x` minors.

| Version | Supported |
| ------- | --------- |
| 0.9.x | Yes |
| < 0.9 | No |

If you are running an older tag, the fix for a reported issue will be an upgrade.

## Reporting a vulnerability

Please report privately, through GitHub's private vulnerability reporting: open the
repository's **Security** tab and use **Report a vulnerability**. That opens a private
thread visible only to you and the maintainers.

Please do not open a public issue, a pull request, or a discussion for a security
report. A public issue is a disclosure, and it is one made before there is anything for
people to upgrade to.

## What to include

Enough to reproduce it. Usually that is:

- what the problem is, and what an attacker gets out of it;
- the version, tag, or commit you tested;
- how you are running it (Docker image, `go build`, behind which proxy) and anything
non-default in your configuration;
- the steps, request, or proof-of-concept that triggers it;
- what you expected to happen instead.

If you are not sure whether something is a vulnerability, report it anyway and say so.
An unclear report is easier to deal with than one that never arrives.

## What to expect

- **An acknowledgement within a few days.** If you have not heard anything after a week,
please post a follow-up on the same private thread in case it was missed.
- **Then either a fix or an explanation.** If we agree it is a vulnerability, we will
tell you roughly when a fix will land and let you know when it ships. If we do not
think it is one, we will say why rather than leaving the report open.
- **A public advisory when the fix is released**, through GitHub Security Advisories, so
people running Calnode know what they are upgrading for.
- **Credit, if you want it.** Tell us the name or handle to use, or tell us you would
rather stay anonymous. Either is fine.

Please give us a reasonable chance to ship a fix before publishing the details.
Loading