mirror of
https://github.com/saltbo/zpan.git
synced 2026-08-28 15:51:29 +08:00
Create SECURITY.md for security policy (#471)
* Create SECURITY.md for security policy Added a security policy document outlining supported versions and vulnerability reporting. Signed-off-by: Jasper Van <saltbo@foxmail.com> * docs: fill in real SECURITY.md policy for ZPan Replace the GitHub default template (placeholder 5.x/4.x versions and boilerplate) with an actual policy: supported 2.x versions, private vulnerability reporting via GitHub Security Advisories, and response-time expectations. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Signed-off-by: saltbo <saltbo@foxmail.com> * docs: express supported versions relative to latest release Avoid pinning a concrete minor (2.7.x) that goes stale on every release. ZPan ships fixes forward on a single release train and does not backport, so 'latest release only' is both accurate and zero-maintenance. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Signed-off-by: saltbo <saltbo@foxmail.com> --------- Signed-off-by: Jasper Van <saltbo@foxmail.com> Signed-off-by: saltbo <saltbo@foxmail.com> Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
+57
@@ -0,0 +1,57 @@
|
||||
# Security Policy
|
||||
|
||||
ZPan is an open-source, S3-native file hosting platform. We take the security of
|
||||
ZPan and its users seriously and appreciate responsible disclosure of any issues.
|
||||
|
||||
## Supported Versions
|
||||
|
||||
Security fixes ship in the latest release only — we do not backport fixes to
|
||||
older versions. If you are affected by a security issue, please upgrade to the
|
||||
most recent release. ZPan v1 (the legacy Go implementation on the
|
||||
[`v1` branch](https://github.com/saltbo/zpan/tree/v1)) is no longer maintained
|
||||
and receives no security updates.
|
||||
|
||||
| Version | Supported |
|
||||
| -------------------- | ------------------ |
|
||||
| Latest 2.x release | :white_check_mark: |
|
||||
| Older 2.x releases | :x: |
|
||||
| 1.x (Go, legacy) | :x: |
|
||||
|
||||
## Reporting a Vulnerability
|
||||
|
||||
**Please do not report security vulnerabilities through public GitHub issues,
|
||||
discussions, or pull requests.**
|
||||
|
||||
Instead, report them privately through GitHub Security Advisories:
|
||||
|
||||
➡️ **[Report a vulnerability](https://github.com/saltbo/zpan/security/advisories/new)**
|
||||
|
||||
This opens a private channel visible only to the maintainers. Please include as
|
||||
much of the following as you can:
|
||||
|
||||
- The type of issue (e.g. authentication bypass, SSRF, presigned-URL leakage,
|
||||
injection, privilege escalation)
|
||||
- The affected component (Cloudflare Workers deployment, Node/Docker deployment,
|
||||
storage gateway, frontend, etc.) and version
|
||||
- Step-by-step instructions to reproduce the issue, including any proof-of-concept
|
||||
- The impact, including how an attacker might exploit it
|
||||
|
||||
## What to Expect
|
||||
|
||||
- **Acknowledgement** — we aim to confirm receipt within **3 business days**.
|
||||
- **Assessment** — we will investigate and let you know whether the report is
|
||||
accepted, needs more information, or is declined, typically within **7 days**.
|
||||
- **Fix & disclosure** — for accepted reports we will work on a fix, keep you
|
||||
updated on progress, and coordinate a public disclosure (and a GitHub Security
|
||||
Advisory with a CVE where appropriate) once a patched release is available. We
|
||||
are happy to credit you for the discovery unless you prefer to remain anonymous.
|
||||
|
||||
Please give us a reasonable amount of time to address the issue before any public
|
||||
disclosure.
|
||||
|
||||
## Scope
|
||||
|
||||
This policy covers the ZPan codebase in this repository. Vulnerabilities in
|
||||
third-party dependencies should be reported to the respective upstream projects;
|
||||
if a dependency issue directly affects ZPan, feel free to let us know so we can
|
||||
update or mitigate.
|
||||
Reference in New Issue
Block a user