Commit 5a02e39f58
Unsigned
Layout: unified · split
SECURITY.org → SECURITY.md renamed +16 −12
| @@ -1,28 +1,32 @@ | ||
| 1 | * Security Policy | |
| 2 | ** Supported Versions | |
| 3 | | Version | Supported | | |
| 4 | |—————-+———--| | |
| 5 | | latest release | yes | | |
| 6 | | anything older | no | | |
| 1 | # Security Policy | |
| 2 | ||
| 3 | ## Supported Versions | |
| 4 | ||
| 5 | | Version | Supported | | |
| 6 | |---------|-----------| | |
| 7 | | latest release | yes | | |
| 8 | | anything older | no | | |
| 7 | 9 | |
| 8 | 10 | Fixes land in a new release rather than as patches to an old one. |
| 9 | 11 | |
| 10 | ** Reporting | |
| 11 | Email [[mailto:hello@cleberg.net][hello@cleberg.net]], or open a private advisory through GitHub's /Security/ tab. | |
| 12 | ## Reporting | |
| 13 | ||
| 14 | Email <hello@cleberg.net>, or open a private advisory through GitHub's *Security* tab. | |
| 12 | 15 | Please do not open a public issue for something exploitable. |
| 13 | 16 | |
| 14 | ** What is worth reporting | |
| 15 | orgo reads org files and writes HTML, so the interesting cases are about what a /document/ | |
| 17 | ## What is worth reporting | |
| 18 | ||
| 19 | orgo reads org files and writes HTML, so the interesting cases are about what a *document* | |
| 16 | 20 | can make it do: |
| 17 | 21 | |
| 18 | 22 | - Content from a source file escaping into HTML unescaped — a page that can inject script |
| 19 | 23 | into the site it is published on. |
| 20 | 24 | - A path in a document or config that writes outside the output directory. |
| 21 | - The =serve= development server reachable, or made reachable, beyond loopback, or serving | |
| 25 | - The `serve` development server reachable, or made reachable, beyond loopback, or serving | |
| 22 | 26 | files from outside the output directory. |
| 23 | 27 | - A crash, hang or unbounded allocation triggered by a crafted org file. A build that |
| 24 | 28 | refuses a file is fine; one that never finishes is not. |
| 25 | 29 | |
| 26 | Out of scope: =--strict= not catching something, an unhandled org construct rendering | |
| 30 | Out of scope: `--strict` not catching something, an unhandled org construct rendering | |
| 27 | 31 | oddly, and anything requiring you to run orgo against files you already do not trust while |
| 28 | 32 | also deploying the result unread. |