Upstream commit: 3f657330c0f49a015a3a372fb59669b5cccbca6d Enterprise-only files removed or emptied: 63 Enterprise-only snippets removed: 118 in 50 files Dangling module declarations removed: 5 Edits turning enterprise off: 25 Third-party code: 14 files, 0 not in THIRD-PARTY.md Renamed identifiers: 67 in 19 files Verification: clean The same Enterprise footprint as v0.16.24. The build check is clean apart from the expected errors in the rebuilt-feature tests. A bug-fix release: DKIM rotation, IMAP failed-login answers, DNSBL multi-code scoring and negative TTLs, Pyzor on short messages, queue quotas with an empty match, RocksDB info-log rotation, and Autodiscover schema handling.
43 lines
1.4 KiB
Markdown
43 lines
1.4 KiB
Markdown
# Security policy
|
|
|
|
## Supported versions
|
|
|
|
INBUXA is developed on `main`, and security fixes are applied there and in
|
|
the latest release. Older tags are not backported.
|
|
|
|
| Version | Supported |
|
|
| --- | --- |
|
|
| `main` and the latest release | :white_check_mark: |
|
|
| Older releases | :x: |
|
|
|
|
## Reporting a vulnerability
|
|
|
|
**Please don't open a public issue for a security problem.** An issue is
|
|
visible to everyone, including whoever would use it, before there is a fix.
|
|
|
|
Report it privately by email to:
|
|
|
|
**johnellisATlinuxDOTcom**
|
|
|
|
Include as much as you can of:
|
|
|
|
- what the vulnerability is, and what it lets someone do;
|
|
- how to reproduce it, or a proof of concept;
|
|
- the version or commit affected;
|
|
- anything about the deployment that matters — backend, front ends, whether
|
|
it needs an authenticated account.
|
|
|
|
You'll get an acknowledgement within a few days. If a report turns out to
|
|
affect upstream Stalwart rather than this fork's own code, it will be passed
|
|
to Stalwart Labs with credit to you, and you'll be told that has happened.
|
|
|
|
## Scope
|
|
|
|
This repository is the mail server. The web front ends have their own:
|
|
|
|
- [inbuxa-admin](https://git.coffeylabs.org/inbuxa/inbuxa-admin)
|
|
- [inbuxa-webmail](https://git.coffeylabs.org/inbuxa/inbuxa-webmail)
|
|
|
|
Upstream's own security documents are kept in `.github-upstream/` for
|
|
reference. They describe Stalwart Labs' process, not this project's.
|