krz/orgo

Lightning fast org-mode static site generator. fast go org-mode static-site-generator

Commit 5a02e39f58

5a02e39f580690a81970fd2a56c5454935d76b9b

parent: a52aee8095

Unsigned

cmc <hello@cleberg.net> · 2026-08-11 22:23 UTC

Keep SECURITY.md as markdown

GitHub's *Report a vulnerability* affordance and the Security-tab link look for
that filename specifically, and a security policy nobody can find is worse than
one written in the wrong markup.

Restored from the original file rather than converted back: a round trip through
two converters is a worse copy than the one that was already there. It is
byte-identical to what was committed yesterday.

Layout: unified · split

SECURITY.org → SECURITY.md renamed +16 −12
@@ -1,28 +1,32 @@
1* Security Policy
2** Supported Versions
3| Version | Supported |
4|—————-+———--|
5| latest release | yes |
6| anything older | no |
1# Security Policy
2
3## Supported Versions
4
5| Version | Supported |
6|---------|-----------|
7| latest release | yes |
8| anything older | no |
79
810Fixes land in a new release rather than as patches to an old one.
911
10** Reporting
11Email [[mailto:hello@cleberg.net][hello@cleberg.net]], or open a private advisory through GitHub's /Security/ tab.
12## Reporting
13
14Email <hello@cleberg.net>, or open a private advisory through GitHub's *Security* tab.
1215Please do not open a public issue for something exploitable.
1316
14** What is worth reporting
15orgo reads org files and writes HTML, so the interesting cases are about what a /document/
17## What is worth reporting
18
19orgo reads org files and writes HTML, so the interesting cases are about what a *document*
1620can make it do:
1721
1822- Content from a source file escaping into HTML unescaped — a page that can inject script
1923 into the site it is published on.
2024- A path in a document or config that writes outside the output directory.
21- The =serve= development server reachable, or made reachable, beyond loopback, or serving
25- The `serve` development server reachable, or made reachable, beyond loopback, or serving
2226 files from outside the output directory.
2327- A crash, hang or unbounded allocation triggered by a crafted org file. A build that
2428 refuses a file is fine; one that never finishes is not.
2529
26Out of scope: =--strict= not catching something, an unhandled org construct rendering
30Out of scope: `--strict` not catching something, an unhandled org construct rendering
2731oddly, and anything requiring you to run orgo against files you already do not trust while
2832also deploying the result unread.