From 35d9d374c9af5ac0b07338bfd1c0dc67a8c0f3b3 Mon Sep 17 00:00:00 2001 From: Dante Sanchez Date: Tue, 22 Sep 2026 13:33:31 -0400 Subject: [PATCH] add security contact info --- .github/SECURITY.md | 14 ++++++++++ .well-known/security.txt | 5 ++++ README.md | 6 +++++ _config.yml | 2 ++ _includes/sections/footer.html | 2 ++ security.html | 47 ++++++++++++++++++++++++++++++++++ 6 files changed, 76 insertions(+) create mode 100644 .github/SECURITY.md create mode 100644 .well-known/security.txt create mode 100644 security.html diff --git a/.github/SECURITY.md b/.github/SECURITY.md new file mode 100644 index 00000000..fdbb9baf --- /dev/null +++ b/.github/SECURITY.md @@ -0,0 +1,14 @@ +# Security Policy + +If you believe you've found a security vulnerability affecting the hypha.coop website or our work, please email **security@hypha.coop** rather than opening a public issue. + +Please include: + +- A description of the issue and its potential impact. +- Steps to reproduce it, or a proof of concept. +- The affected URL, repository, or system. +- How we can reach you if we have questions. + +We ask that you keep the details private until we've had a chance to fix the issue, and that you avoid accessing or changing data that isn't yours, disrupting our services, or social engineering our team or partners. + +More information: https://hypha.coop/security/ diff --git a/.well-known/security.txt b/.well-known/security.txt new file mode 100644 index 00000000..a39e75ed --- /dev/null +++ b/.well-known/security.txt @@ -0,0 +1,5 @@ +Contact: mailto:security@hypha.coop +Expires: 2027-09-01T00:00:00.000Z +Preferred-Languages: en +Canonical: https://hypha.coop/.well-known/security.txt +Policy: https://hypha.coop/security/ diff --git a/README.md b/README.md index 8bd5a115..0790e55e 100644 --- a/README.md +++ b/README.md @@ -35,6 +35,12 @@ We also auto-deploy `staging` branch to [staging.hypha.coop](https://staging.hyp Staging uses Let's Encrypt staging enviroment to allow for higher limits than their production environment. This allow us to redeploy sites on staging without hitting the limit of Let's Encrypt production. As a result when accessing staging you will be prompted about invalid certificate on your browser. More information on Let's Encrypt staging enviroment [here.](https://letsencrypt.org/docs/staging-environment/) +## 🔒 Security + +To report a security vulnerability, email [security@hypha.coop](mailto:security@hypha.coop). See [`.github/SECURITY.md`](./.github/SECURITY.md) and the [security page](https://hypha.coop/security/). + +[`.well-known/security.txt`](./.well-known/security.txt) has an `Expires` date that must be renewed at least once a year (RFC 9116 allows at most one year ahead). + ## 📑 Attribution - `favicon.ico`: [Rorschach Test](https://thenounproject.com/nicky.humphreys/collection/repeat-pattern/?i=871159) by Nicky Knicky from the Noun Project diff --git a/_config.yml b/_config.yml index 415b539b..e72abfae 100644 --- a/_config.yml +++ b/_config.yml @@ -1,6 +1,8 @@ title: Hypha email: hello@hypha.coop email-hidden: "%68%65%6c%6c%6f%40%68%79%70%68%61%2e%63%6f%6f%70" +security_email: security@hypha.coop +security_email-hidden: "%73%65%63%75%72%69%74%79%40%68%79%70%68%61%2e%63%6f%6f%70" phone: +1 437-887-6936 address: Toronto, ON github: https://github.com/hyphacoop diff --git a/_includes/sections/footer.html b/_includes/sections/footer.html index 937835b7..0efac196 100644 --- a/_includes/sections/footer.html +++ b/_includes/sections/footer.html @@ -44,6 +44,8 @@

Policies and Licensing Information

href="https://handbook.hypha.coop/Policies/data.html" target="_blank" class="accent link" rel="noopener">How We Use Data and Working Open.

+

Found a security issue? Please report it + to {{ site.security_email }}.

This site is published using Distributed Press. diff --git a/security.html b/security.html new file mode 100644 index 00000000..406c2e85 --- /dev/null +++ b/security.html @@ -0,0 +1,47 @@ +--- +layout: default +title: Security +excerpt: "If you believe you've found a security vulnerability affecting our website or our work, please email security@hypha.coop." +--- +

+
+
+
+

+ {{ page.title }} +

+

+ If you believe you've found a security vulnerability affecting this website or our work, please let us know by emailing + {{ site.security_email }}. +

+
+
+
+ +
+

What to include

+
    +
  • A description of the issue and its potential impact.
  • +
  • Steps to reproduce it, or a proof of concept.
  • +
  • The affected URL, repository, or system.
  • +
  • How we can reach you if we have questions.
  • +
+ +

What to expect

+

+ We'll read every report and get back to you. We ask that you keep the details private until we've had a chance to fix the issue. +

+ +

Acting in good faith

+

+ Please avoid accessing or changing data that isn't yours, disrupting our services or the people who use them, and social engineering our team or partners. +

+ +

Our open source work

+

+ Much of our work is open source and lives on GitHub. + Please use the same email address to report vulnerabilities in any of it, rather than opening a public issue. + For how we handle data more generally, see How We Use Data in our handbook. +

+
+