diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml new file mode 100644 index 0000000..313c925 --- /dev/null +++ b/.github/workflows/ci.yml @@ -0,0 +1,24 @@ +name: CI + +on: + push: + branches: [main] + pull_request: + branches: [main] + +permissions: + contents: read + +jobs: + gitleaks: + name: Secret scan (gitleaks) + runs-on: ubuntu-latest + steps: + - uses: actions/checkout@v4 + with: + fetch-depth: 0 + + - name: Run gitleaks + uses: gitleaks/gitleaks-action@v2 + env: + GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} diff --git a/LICENSE b/LICENSE index f6c265e..8ff7201 100644 --- a/LICENSE +++ b/LICENSE @@ -1,4 +1,4 @@ -MIT Liicense +MIT License Copyright (c) 2026 Jordan Newell diff --git a/README.md b/README.md index d14ba21..1d5154f 100644 --- a/README.md +++ b/README.md @@ -162,3 +162,11 @@ Dotfiles are the standard answer. Clone the repo, run the installer, done. The g --- MIT licensed. Fork, adapt, make your own. + +## Contributing + +Issues and PRs welcome. Fork, branch, open a PR against `main`. + +## License + +MIT — see [LICENSE](./LICENSE). diff --git a/SECURITY.md b/SECURITY.md new file mode 100644 index 0000000..09c1cf8 --- /dev/null +++ b/SECURITY.md @@ -0,0 +1,34 @@ +# Security Policy + +## Reporting a vulnerability + +Email **security@jordannewell.com** with: + +- A description of the issue and its impact +- Reproduction steps (a minimal example is ideal) +- Affected version or commit + +**Do not open a public GitHub issue** for security reports. + +If you have a PGP key, encrypt your report. GPG fingerprint of the project's +reporting key: + +``` +67567DC5E7C5353F85F2AF0DAC05D3F3E0EFA32A +``` + +## Response timeline + +- **Acknowledgment:** within 72 hours +- **Initial assessment:** within 5 business days +- **Fix or mitigation:** target 30 days for high-severity issues + +Please refrain from public disclosure until a fix has been published, to +protect downstream users. Reporters will be credited in the release notes +unless they prefer otherwise. + +## Scope + +Only vulnerabilities in this repository's code and published releases are in +scope. Issues in third-party dependencies should be reported upstream, though +a heads-up email is appreciated for anything actively exploited.