- LICENSE -> verbatim GNU AGPL-3.0; add LICENSE-COMMERCIAL.md + SECURITY.md - CLA -> exclusive-license grant (contributors keep copyright); add README anti-rugpull covenant + relicense record - NOTICE / README / CONTRIBUTING / CLAUDE.md / package.json x5 updated; contact routed through GitHub (no email placeholders) - AGPL section 13 source offer: operator-configurable BACKSPACE_SOURCE_URL + build-injected commit; sourceCodeUrl+commit on /api/instance/info; SourceCodeLink on login/register/settings/desktop; docs + .env.example updated
672 B
672 B
Security Policy
Reporting a vulnerability
Please do not open a public issue for security vulnerabilities.
Report privately via a GitHub security advisory on this repository (Security → Report a vulnerability).
For non-security questions, use GitHub Issues (bugs) or GitHub Discussions (questions).
We will acknowledge your report, work with you on a fix, and coordinate disclosure. Please include reproduction steps, affected version/commit, and your environment (deployment method, browser/desktop, and whether federation or voice is involved).
Supported versions
Backspace 1.x receives security fixes. Always run the latest release.