diff --git a/.github/SECURITY.md b/.github/SECURITY.md new file mode 100644 index 00000000..fdbb9baf --- /dev/null +++ b/.github/SECURITY.md @@ -0,0 +1,14 @@ +# Security Policy + +If you believe you've found a security vulnerability affecting the hypha.coop website or our work, please email **security@hypha.coop** rather than opening a public issue. + +Please include: + +- A description of the issue and its potential impact. +- Steps to reproduce it, or a proof of concept. +- The affected URL, repository, or system. +- How we can reach you if we have questions. + +We ask that you keep the details private until we've had a chance to fix the issue, and that you avoid accessing or changing data that isn't yours, disrupting our services, or social engineering our team or partners. + +More information: https://hypha.coop/security/ diff --git a/.well-known/security.txt b/.well-known/security.txt new file mode 100644 index 00000000..a39e75ed --- /dev/null +++ b/.well-known/security.txt @@ -0,0 +1,5 @@ +Contact: mailto:security@hypha.coop +Expires: 2027-09-01T00:00:00.000Z +Preferred-Languages: en +Canonical: https://hypha.coop/.well-known/security.txt +Policy: https://hypha.coop/security/ diff --git a/README.md b/README.md index 8bd5a115..0790e55e 100644 --- a/README.md +++ b/README.md @@ -35,6 +35,12 @@ We also auto-deploy `staging` branch to [staging.hypha.coop](https://staging.hyp Staging uses Let's Encrypt staging enviroment to allow for higher limits than their production environment. This allow us to redeploy sites on staging without hitting the limit of Let's Encrypt production. As a result when accessing staging you will be prompted about invalid certificate on your browser. More information on Let's Encrypt staging enviroment [here.](https://letsencrypt.org/docs/staging-environment/) +## 🔒 Security + +To report a security vulnerability, email [security@hypha.coop](mailto:security@hypha.coop). See [`.github/SECURITY.md`](./.github/SECURITY.md) and the [security page](https://hypha.coop/security/). + +[`.well-known/security.txt`](./.well-known/security.txt) has an `Expires` date that must be renewed at least once a year (RFC 9116 allows at most one year ahead). + ## 📑 Attribution - `favicon.ico`: [Rorschach Test](https://thenounproject.com/nicky.humphreys/collection/repeat-pattern/?i=871159) by Nicky Knicky from the Noun Project diff --git a/_config.yml b/_config.yml index 415b539b..e72abfae 100644 --- a/_config.yml +++ b/_config.yml @@ -1,6 +1,8 @@ title: Hypha email: hello@hypha.coop email-hidden: "%68%65%6c%6c%6f%40%68%79%70%68%61%2e%63%6f%6f%70" +security_email: security@hypha.coop +security_email-hidden: "%73%65%63%75%72%69%74%79%40%68%79%70%68%61%2e%63%6f%6f%70" phone: +1 437-887-6936 address: Toronto, ON github: https://github.com/hyphacoop diff --git a/_includes/sections/footer.html b/_includes/sections/footer.html index 937835b7..0efac196 100644 --- a/_includes/sections/footer.html +++ b/_includes/sections/footer.html @@ -44,6 +44,8 @@
Found a security issue? Please report it + to {{ site.security_email }}.
This site is published using Distributed Press.
diff --git a/security.html b/security.html
new file mode 100644
index 00000000..406c2e85
--- /dev/null
+++ b/security.html
@@ -0,0 +1,47 @@
+---
+layout: default
+title: Security
+excerpt: "If you believe you've found a security vulnerability affecting our website or our work, please email security@hypha.coop."
+---
+
+ If you believe you've found a security vulnerability affecting this website or our work, please let us know by emailing
+ {{ site.security_email }}.
+
+ We'll read every report and get back to you. We ask that you keep the details private until we've had a chance to fix the issue.
+
+ Please avoid accessing or changing data that isn't yours, disrupting our services or the people who use them, and social engineering our team or partners.
+
+ Much of our work is open source and lives on GitHub.
+ Please use the same email address to report vulnerabilities in any of it, rather than opening a public issue.
+ For how we handle data more generally, see How We Use Data in our handbook.
+
+ {{ page.title }}
+
+ What to include
+
+
+
+ What to expect
+ Acting in good faith
+ Our open source work
+