Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
14 changes: 14 additions & 0 deletions .github/SECURITY.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,14 @@
# Security Policy

If you believe you've found a security vulnerability affecting the hypha.coop website or our work, please email **security@hypha.coop** rather than opening a public issue.

Please include:

- A description of the issue and its potential impact.
- Steps to reproduce it, or a proof of concept.
- The affected URL, repository, or system.
- How we can reach you if we have questions.

We ask that you keep the details private until we've had a chance to fix the issue, and that you avoid accessing or changing data that isn't yours, disrupting our services, or social engineering our team or partners.

More information: https://hypha.coop/security/
5 changes: 5 additions & 0 deletions .well-known/security.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
Contact: mailto:security@hypha.coop
Expires: 2027-09-01T00:00:00.000Z
Preferred-Languages: en
Canonical: https://hypha.coop/.well-known/security.txt
Policy: https://hypha.coop/security/
6 changes: 6 additions & 0 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -35,6 +35,12 @@ We also auto-deploy `staging` branch to [staging.hypha.coop](https://staging.hyp

Staging uses Let's Encrypt staging enviroment to allow for higher limits than their production environment. This allow us to redeploy sites on staging without hitting the limit of Let's Encrypt production. As a result when accessing staging you will be prompted about invalid certificate on your browser. More information on Let's Encrypt staging enviroment [here.](https://letsencrypt.org/docs/staging-environment/)

## 🔒 Security

To report a security vulnerability, email [security@hypha.coop](mailto:security@hypha.coop). See [`.github/SECURITY.md`](./.github/SECURITY.md) and the [security page](https://hypha.coop/security/).

[`.well-known/security.txt`](./.well-known/security.txt) has an `Expires` date that must be renewed at least once a year (RFC 9116 allows at most one year ahead).

## 📑 Attribution

- `favicon.ico`: [Rorschach Test](https://thenounproject.com/nicky.humphreys/collection/repeat-pattern/?i=871159) by Nicky Knicky from the Noun Project
Expand Down
2 changes: 2 additions & 0 deletions _config.yml
Original file line number Diff line number Diff line change
@@ -1,6 +1,8 @@
title: Hypha
email: hello@hypha.coop
email-hidden: "%68%65%6c%6c%6f%40%68%79%70%68%61%2e%63%6f%6f%70"
security_email: security@hypha.coop
security_email-hidden: "%73%65%63%75%72%69%74%79%40%68%79%70%68%61%2e%63%6f%6f%70"
phone: +1 437-887-6936
address: Toronto, ON
github: https://github.com/hyphacoop
Expand Down
2 changes: 2 additions & 0 deletions _includes/sections/footer.html
Original file line number Diff line number Diff line change
Expand Up @@ -44,6 +44,8 @@ <h2 id="policies-heading" class="dn">Policies and Licensing Information</h2>
href="https://handbook.hypha.coop/Policies/data.html" target="_blank" class="accent link"
rel="noopener">How We Use Data</a> and <a href="https://handbook.hypha.coop/Policies/working-open.html"
target="_blank" class="accent link" rel="noopener">Working Open</a>.</p>
<p class="f6 f5-l lh-copy">Found a security issue? Please <a href="/security/" class="accent link">report it</a>
to <a href="mailto:{{ site.security_email-hidden }}" class="accent link">{{ site.security_email }}</a>.</p>
<p class="f6 f5-l lh-copy">
This site is published using <a href="https://distributed.press/" target="_blank"
class="accent link" rel="noopener">Distributed Press</a>.
Expand Down
47 changes: 47 additions & 0 deletions security.html
Original file line number Diff line number Diff line change
@@ -0,0 +1,47 @@
---
layout: default
title: Security
excerpt: "If you believe you've found a security vulnerability affecting our website or our work, please email security@hypha.coop."
---
<section class="mt2 ph3 ph5-l">
<header>
<div class="flex-l items-center mv2">
<div class="w-100-l">
<h3 class="f2 f1-m f-subheadline-l accent normal sans-serif mb4 lh-solid">
{{ page.title }}
</h3>
<p class="f3 measure-wide dark-gray lh-copy mb5">
If you believe you've found a security vulnerability affecting this website or our work, please let us know by emailing
<a class="accent link" href="mailto:{{ site.security_email-hidden }}">{{ site.security_email }}</a>.
</p>
</div>
</div>
</header>

<div class="measure-wide f4 lh-copy mb5">
<h2 class="f3 sans-serif accent normal mt0">What to include</h2>
<ul class="lh-copy pl3">
<li>A description of the issue and its potential impact.</li>
<li>Steps to reproduce it, or a proof of concept.</li>
<li>The affected URL, repository, or system.</li>
<li>How we can reach you if we have questions.</li>
</ul>

<h2 class="f3 sans-serif accent normal mt4">What to expect</h2>
<p>
We'll read every report and get back to you. We ask that you keep the details private until we've had a chance to fix the issue.
</p>

<h2 class="f3 sans-serif accent normal mt4">Acting in good faith</h2>
<p>
Please avoid accessing or changing data that isn't yours, disrupting our services or the people who use them, and social engineering our team or partners.
</p>

<h2 class="f3 sans-serif accent normal mt4">Our open source work</h2>
<p>
Much of our work is open source and lives on <a class="accent link" href="{{ site.github }}" target="_blank" rel="noopener">GitHub</a>.
Please use the same email address to report vulnerabilities in any of it, rather than opening a public issue.
For how we handle data more generally, see <a class="accent link" href="https://handbook.hypha.coop/Policies/data.html" target="_blank" rel="noopener">How We Use Data</a> in our handbook.
</p>
</div>
</section>
Loading