krz/orgo

Lightning fast org-mode static site generator. fast go org-mode static-site-generator

Commit 5a02e39f58

5a02e39f580690a81970fd2a56c5454935d76b9b

parent: a52aee8095

Unsigned

cmc <hello@cleberg.net> · 2026-08-11 22:23 UTC

Keep SECURITY.md as markdown

GitHub's *Report a vulnerability* affordance and the Security-tab link look for
that filename specifically, and a security policy nobody can find is worse than
one written in the wrong markup.

Restored from the original file rather than converted back: a round trip through
two converters is a worse copy than the one that was already there. It is
byte-identical to what was committed yesterday.

Layout: unified · split

SECURITY.org → SECURITY.md renamed +16 −12
@@ -1,28 +1,32 @@
1* Security Policy 1# Security Policy
2** Supported Versions 2
3| Version | Supported | 3## Supported Versions
4|—————-+———--| 4
5| latest release | yes | 5| Version | Supported |
6| anything older | no | 6|---------|-----------|
7| latest release | yes |
8| anything older | no |
7 9
8Fixes land in a new release rather than as patches to an old one. 10Fixes land in a new release rather than as patches to an old one.
9 11
10** Reporting 12## Reporting
11Email [[mailto:hello@cleberg.net][hello@cleberg.net]], or open a private advisory through GitHub's /Security/ tab. 13
14Email <hello@cleberg.net>, or open a private advisory through GitHub's *Security* tab.
12Please do not open a public issue for something exploitable. 15Please do not open a public issue for something exploitable.
13 16
14** What is worth reporting 17## What is worth reporting
15orgo reads org files and writes HTML, so the interesting cases are about what a /document/ 18
19orgo reads org files and writes HTML, so the interesting cases are about what a *document*
16can make it do: 20can make it do:
17 21
18- Content from a source file escaping into HTML unescaped — a page that can inject script 22- Content from a source file escaping into HTML unescaped — a page that can inject script
19 into the site it is published on. 23 into the site it is published on.
20- A path in a document or config that writes outside the output directory. 24- A path in a document or config that writes outside the output directory.
21- The =serve= development server reachable, or made reachable, beyond loopback, or serving 25- The `serve` development server reachable, or made reachable, beyond loopback, or serving
22 files from outside the output directory. 26 files from outside the output directory.
23- A crash, hang or unbounded allocation triggered by a crafted org file. A build that 27- A crash, hang or unbounded allocation triggered by a crafted org file. A build that
24 refuses a file is fine; one that never finishes is not. 28 refuses a file is fine; one that never finishes is not.
25 29
26Out of scope: =--strict= not catching something, an unhandled org construct rendering 30Out of scope: `--strict` not catching something, an unhandled org construct rendering
27oddly, and anything requiring you to run orgo against files you already do not trust while 31oddly, and anything requiring you to run orgo against files you already do not trust while
28also deploying the result unread. 32also deploying the result unread.