license: relicense to AGPL-3.0-only with commercial dual-license
- LICENSE -> verbatim GNU AGPL-3.0; add LICENSE-COMMERCIAL.md + SECURITY.md - CLA -> exclusive-license grant (contributors keep copyright); add README anti-rugpull covenant + relicense record - NOTICE / README / CONTRIBUTING / CLAUDE.md / package.json x5 updated; contact routed through GitHub (no email placeholders) - AGPL section 13 source offer: operator-configurable BACKSPACE_SOURCE_URL + build-injected commit; sourceCodeUrl+commit on /api/instance/info; SourceCodeLink on login/register/settings/desktop; docs + .env.example updated
This commit is contained in:
+20
@@ -0,0 +1,20 @@
|
||||
# Security Policy
|
||||
|
||||
## Reporting a vulnerability
|
||||
|
||||
Please **do not** open a public issue for security vulnerabilities.
|
||||
|
||||
Report privately via a **GitHub security advisory** on this repository
|
||||
(Security → **Report a vulnerability**).
|
||||
|
||||
For non-security questions, use **GitHub Issues** (bugs) or **GitHub Discussions**
|
||||
(questions).
|
||||
|
||||
We will acknowledge your report, work with you on a fix, and coordinate
|
||||
disclosure. Please include reproduction steps, affected version/commit, and your
|
||||
environment (deployment method, browser/desktop, and whether federation or voice
|
||||
is involved).
|
||||
|
||||
## Supported versions
|
||||
|
||||
Backspace 1.x receives security fixes. Always run the latest release.
|
||||
Reference in New Issue
Block a user