- LICENSE -> verbatim GNU AGPL-3.0; add LICENSE-COMMERCIAL.md + SECURITY.md - CLA -> exclusive-license grant (contributors keep copyright); add README anti-rugpull covenant + relicense record - NOTICE / README / CONTRIBUTING / CLAUDE.md / package.json x5 updated; contact routed through GitHub (no email placeholders) - AGPL section 13 source offer: operator-configurable BACKSPACE_SOURCE_URL + build-injected commit; sourceCodeUrl+commit on /api/instance/info; SourceCodeLink on login/register/settings/desktop; docs + .env.example updated
21 lines
672 B
Markdown
21 lines
672 B
Markdown
# Security Policy
|
|
|
|
## Reporting a vulnerability
|
|
|
|
Please **do not** open a public issue for security vulnerabilities.
|
|
|
|
Report privately via a **GitHub security advisory** on this repository
|
|
(Security → **Report a vulnerability**).
|
|
|
|
For non-security questions, use **GitHub Issues** (bugs) or **GitHub Discussions**
|
|
(questions).
|
|
|
|
We will acknowledge your report, work with you on a fix, and coordinate
|
|
disclosure. Please include reproduction steps, affected version/commit, and your
|
|
environment (deployment method, browser/desktop, and whether federation or voice
|
|
is involved).
|
|
|
|
## Supported versions
|
|
|
|
Backspace 1.x receives security fixes. Always run the latest release.
|