mirror of
https://github.com/Studio-Saelix/sencho.git
synced 2026-07-28 20:59:09 +00:00
9f9de482ce
* chore: add comprehensive .gitignore * ci: update CI workflow for GitHub Flow - Change triggers from develop to main (PRs to main + pushes to main) - Add concurrency controls to cancel stale runs - Update docker/build-push-action to v6 - Add descriptive job names for branch protection status checks - Update screenshot refresh and docs sync to trigger on main pushes * ci: update docker-publish for GitHub Flow - Remove develop branch trigger (no more dev tag) - Keep v* tag trigger for releases - Update docker/build-push-action to v6 * docs: add community and governance files - CONTRIBUTING.md with dev setup and PR guidelines - SECURITY.md with vulnerability reporting policy - CODE_OF_CONDUCT.md (Contributor Covenant v2.1 reference) - PR template with conventional commits checklist - Issue templates for bug reports and feature requests - CODEOWNERS defaulting to @AnsoCode - Dependabot config for npm (root, backend, frontend) and GitHub Actions * docs: add README with badges, quick start, and contributing section * chore: add LICENSE placeholder and open license decision issue (#100) * docs: update CLAUDE.md for GitHub Flow branching model - Replace develop-based Git Flow with GitHub Flow (main only) - All branches now created off main, PRs target main - Simplify release checklist (no develop-to-main merge step) - Update testing strategy to reference Vitest and Playwright - Fix docs.json reference (was mint.json) * chore: track CLAUDE.md in version control Remove CLAUDE.md from .gitignore so project workflow instructions are versioned alongside the code they govern. * docs: add MANUAL_STEPS.md for GitHub settings that require UI configuration
30 lines
1.0 KiB
Markdown
30 lines
1.0 KiB
Markdown
# Security Policy
|
|
|
|
## Supported Versions
|
|
|
|
| Version | Supported |
|
|
| ------- | ------------------ |
|
|
| 0.2.x | Yes |
|
|
| < 0.2 | No |
|
|
|
|
## Reporting a Vulnerability
|
|
|
|
**Please do not open a public issue for security vulnerabilities.**
|
|
|
|
Instead, use GitHub's private vulnerability reporting:
|
|
|
|
1. Go to the [Security tab](https://github.com/AnsoCode/Sencho/security) of this repository
|
|
2. Click **"Report a vulnerability"**
|
|
3. Provide details including: steps to reproduce, impact assessment, and any suggested fixes
|
|
|
|
You can expect an initial response within 72 hours. We will work with you to understand and address the issue before any public disclosure.
|
|
|
|
## Security Considerations
|
|
|
|
Sencho manages Docker containers and has access to the Docker socket. When deploying:
|
|
|
|
- Always run behind a reverse proxy with TLS in production
|
|
- Use strong passwords and rotate JWT secrets
|
|
- Restrict network access to the Sencho port
|
|
- Review the [security configuration docs](https://docs.sencho.io) for hardening guidance
|