diff --git a/.gitea/workflows/quality.yml b/.gitea/workflows/quality.yml index 709729d..4d84fc0 100644 --- a/.gitea/workflows/quality.yml +++ b/.gitea/workflows/quality.yml @@ -9,7 +9,7 @@ jobs: secret-scan: runs-on: ubuntu-latest steps: - - uses: actions/checkout@v4 + - uses: https://gitea.com/actions/checkout@v4 - name: Secret scan shell: bash run: | @@ -23,8 +23,8 @@ jobs: # Browser quality runs against the dedicated bounded Windows 11 VM runner. runs-on: windows-native steps: - - uses: actions/checkout@v4 - - uses: actions/setup-node@v4 + - uses: https://gitea.com/actions/checkout@v4 + - uses: https://gitea.com/actions/setup-node@v4 with: node-version: 22 cache: npm @@ -38,7 +38,7 @@ jobs: - run: npm run test:browser:ci - name: Preserve browser failure evidence if: failure() - uses: actions/upload-artifact@v3.2.2-node20 + uses: https://gitea.com/actions/upload-artifact@v3.2.2-node20 with: name: forgeflow-browser-failure-evidence path: artifacts/ diff --git a/.gitea/workflows/release.yml b/.gitea/workflows/release.yml index 35f093c..78c7448 100644 --- a/.gitea/workflows/release.yml +++ b/.gitea/workflows/release.yml @@ -15,10 +15,10 @@ jobs: release: runs-on: windows-native steps: - - uses: actions/checkout@v4 + - uses: https://gitea.com/actions/checkout@v4 with: fetch-depth: 2 - - uses: actions/setup-node@v4 + - uses: https://gitea.com/actions/setup-node@v4 with: node-version: 22 cache: npm diff --git a/SECURITY.md b/SECURITY.md new file mode 100644 index 0000000..40a8a88 --- /dev/null +++ b/SECURITY.md @@ -0,0 +1,9 @@ +# Security Policy + +ForgeFlow's detailed security model is documented in [`docs/SECURITY.md`](docs/SECURITY.md). + +Report suspected vulnerabilities privately to the repository owner. Do not publish Gitea tokens, SSH credentials, update-signing material, private server addresses, support bundles containing sensitive data or other operational secrets in a public issue. + +For a useful report, include the affected ForgeFlow version/commit, component, minimal reproduction steps, expected and observed behaviour and security impact. Use sanitized or synthetic repository/server data whenever possible. + +The current release model requires exact-commit verification, origin-constrained credential use, signed update manifests, redacted diagnostics and bounded deployment adapters. Changes must not silently weaken those guarantees.