diff --git a/.github/ISSUE_TEMPLATE/config.yml b/.github/ISSUE_TEMPLATE/config.yml new file mode 100644 index 0000000..98aa402 --- /dev/null +++ b/.github/ISSUE_TEMPLATE/config.yml @@ -0,0 +1,5 @@ +blank_issues_enabled: true +contact_links: + - name: Report a security vulnerability + url: https://github.com/Commanderx-code/command-center/security/advisories/new + about: Report vulnerabilities privately, not as a public issue. See SECURITY.md. diff --git a/CONTRIBUTING.md b/CONTRIBUTING.md index ff8c710..6586d48 100644 --- a/CONTRIBUTING.md +++ b/CONTRIBUTING.md @@ -6,6 +6,8 @@ Thanks for helping improve Command Center. Small fixes, documentation improvemen Check [existing issues](https://github.com/Commanderx-code/command-center/issues) first, then use the bug report or feature request template. For bugs, include the app version, distribution, installation method, steps to reproduce, and expected versus actual behavior. Mention whether the problem occurs in the desktop app or browser preview. +**Security vulnerabilities:** don't open a public issue. Report them privately as described in [SECURITY.md](SECURITY.md). + Remove secrets and personal information from screenshots and logs. Terminal transcripts and configuration files can contain credentials; include only the relevant, redacted excerpt. ## Work on a change diff --git a/SECURITY.md b/SECURITY.md new file mode 100644 index 0000000..45e34ec --- /dev/null +++ b/SECURITY.md @@ -0,0 +1,39 @@ +# Security policy + +## Reporting a vulnerability + +Please report vulnerabilities privately through GitHub: **[Report a vulnerability](https://github.com/Commanderx-code/command-center/security/advisories/new)** (Security tab → *Report a vulnerability*). Don't open a public issue, discussion, or pull request for a security problem. + +Include what you can: + +- the Command Center version (Settings → About & updates) and your distribution; +- what an attacker controls and what they gain; +- steps to reproduce, or a proof of concept; +- any fix you'd suggest. + +You'll get a reply in the private advisory. Once a fix is ready, it ships in a patch release, and the advisory is published with credit to you unless you'd rather stay anonymous. Please keep the details private until then. + +## Supported versions + +Security fixes go into the latest release only. Update to the newest version before reporting, and check whether the problem still occurs. + +| Version | Supported | +|---|---| +| 0.7.x (latest) | ✅ | +| Older | ❌ | + +## Scope + +Command Center runs locally as your normal user, so the most important boundary is **untrusted data reaching the app**. Examples of in-scope problems: + +- a repository, submodule, Git remote, or its output making the app run commands or misbehave without your review; +- a setup bundle or settings import changing what runs automatically or reading files it shouldn't; +- credentials or private data leaking to other local users, logs, Activity, or exports; +- a way around command review, so something runs that you didn't approve; +- problems in the release packages, the Arch recipe, or the CI workflows that build them. + +Out of scope: + +- actions that need someone already running code as your user, or with root; +- commands you reviewed and approved yourself; +- installer scripts from [Commander Toolbox](https://github.com/Commanderx-code/commander-toolbox): report those to that repository.