Import upstream v0.16.25, stripped

Upstream commit: 3f657330c0f49a015a3a372fb59669b5cccbca6d
Enterprise-only files removed or emptied: 63
Enterprise-only snippets removed: 118 in 50 files
Dangling module declarations removed: 5
Edits turning enterprise off: 25
Third-party code: 14 files, 0 not in THIRD-PARTY.md
Renamed identifiers: 67 in 19 files
Verification: clean

The same Enterprise footprint as v0.16.24. The build check is clean
apart from the expected errors in the rebuilt-feature tests. A
bug-fix release: DKIM rotation, IMAP failed-login answers, DNSBL
multi-code scoring and negative TTLs, Pyzor on short messages, queue
quotas with an empty match, RocksDB info-log rotation, and
Autodiscover schema handling.
This commit is contained in:
jcoffey-dev committed 2026-10-05 21:15:02 -07:00
1 parent f59b084ce5
commit 72f8ddd5e7
67 files changed
+1643 -492

No files matched your search

+23 -1
View File
@@ -16,6 +16,28 @@ We provide security updates for the following versions of Stalwart:
We take the security of Stalwart very seriously. If you believe you've found a security vulnerability, we encourage you to inform us responsibly through coordinated disclosure.
### Do Not Send LLM-Generated Reports
**Please do not send us security reports that were generated by an LLM.**
Stalwart Labs has access to the same state-of-the-art AI models you do, and we run security scans on our repositories regularly. We receive the same LLM-detected false positives almost every day. Reading and dismissing them is a waste of maintainers' time, and it takes time away from processing the real reports sent by real security researchers.
In our experience, an LLM-generated report is almost always one of these:
- A false positive: the model misread the code, or missed a check elsewhere that already prevents the issue.
- A finding in functionality that is not implemented, such as stubs, unused code paths or planned features.
- A real but minor issue that the model rates as far more severe than it is.
We are begging you not to send them. Pointing a model at the repository and forwarding its output does not help us, and it slows down the reports that do matter.
We will not reply to, or confirm receipt of, any report that we deem LLM-generated. This applies to every channel listed below, including GitHub Security Advisories and the backup contact.
A report written by a person who has reproduced the issue against a running, supported release of Stalwart and understands why it is a vulnerability is welcome, whatever tools were used to find it.
### CVEs and Advisories
**Do not request a CVE, and do not publish a RustSec or any other public advisory about Stalwart, on our behalf without our confirmation.** Every CVE or advisory filed without our confirmation will be contested.
### How to Report
**Do not report security vulnerabilities through public GitHub issues, discussions, or social media.**
@@ -45,7 +67,7 @@ To help us understand and address the issue quickly, please include:
### Our Response Process
**Timeline Commitments:**
**Timeline Commitments** (these do not apply to reports we deem LLM-generated, see above):
- **Initial acknowledgment**: Within 24 hours
- **Detailed response**: Within 72 hours
- **Status updates**: Every 7 days until resolved