Import upstream v0.16.25, stripped
Upstream commit: 3f657330c0f49a015a3a372fb59669b5cccbca6d Enterprise-only files removed or emptied: 63 Enterprise-only snippets removed: 118 in 50 files Dangling module declarations removed: 5 Edits turning enterprise off: 25 Third-party code: 14 files, 0 not in THIRD-PARTY.md Renamed identifiers: 67 in 19 files Verification: clean The same Enterprise footprint as v0.16.24. The build check is clean apart from the expected errors in the rebuilt-feature tests. A bug-fix release: DKIM rotation, IMAP failed-login answers, DNSBL multi-code scoring and negative TTLs, Pyzor on short messages, queue quotas with an empty match, RocksDB info-log rotation, and Autodiscover schema handling.
This commit is contained in:
1 parent
f59b084ce5
commit
72f8ddd5e7
67 files changed
+1643
-492
No files matched your search
+23
-1
@@ -16,6 +16,28 @@ We provide security updates for the following versions of Stalwart:
|
||||
|
||||
We take the security of Stalwart very seriously. If you believe you've found a security vulnerability, we encourage you to inform us responsibly through coordinated disclosure.
|
||||
|
||||
### Do Not Send LLM-Generated Reports
|
||||
|
||||
**Please do not send us security reports that were generated by an LLM.**
|
||||
|
||||
Stalwart Labs has access to the same state-of-the-art AI models you do, and we run security scans on our repositories regularly. We receive the same LLM-detected false positives almost every day. Reading and dismissing them is a waste of maintainers' time, and it takes time away from processing the real reports sent by real security researchers.
|
||||
|
||||
In our experience, an LLM-generated report is almost always one of these:
|
||||
|
||||
- A false positive: the model misread the code, or missed a check elsewhere that already prevents the issue.
|
||||
- A finding in functionality that is not implemented, such as stubs, unused code paths or planned features.
|
||||
- A real but minor issue that the model rates as far more severe than it is.
|
||||
|
||||
We are begging you not to send them. Pointing a model at the repository and forwarding its output does not help us, and it slows down the reports that do matter.
|
||||
|
||||
We will not reply to, or confirm receipt of, any report that we deem LLM-generated. This applies to every channel listed below, including GitHub Security Advisories and the backup contact.
|
||||
|
||||
A report written by a person who has reproduced the issue against a running, supported release of Stalwart and understands why it is a vulnerability is welcome, whatever tools were used to find it.
|
||||
|
||||
### CVEs and Advisories
|
||||
|
||||
**Do not request a CVE, and do not publish a RustSec or any other public advisory about Stalwart, on our behalf without our confirmation.** Every CVE or advisory filed without our confirmation will be contested.
|
||||
|
||||
### How to Report
|
||||
|
||||
**Do not report security vulnerabilities through public GitHub issues, discussions, or social media.**
|
||||
@@ -45,7 +67,7 @@ To help us understand and address the issue quickly, please include:
|
||||
|
||||
### Our Response Process
|
||||
|
||||
**Timeline Commitments:**
|
||||
**Timeline Commitments** (these do not apply to reports we deem LLM-generated, see above):
|
||||
- **Initial acknowledgment**: Within 24 hours
|
||||
- **Detailed response**: Within 72 hours
|
||||
- **Status updates**: Every 7 days until resolved
|
||||
|
||||
Reference in new issue
Block a user