From: Rigel Kent Date: Tue, 18 Sep 2018 09:18:51 +0000 (+0200) Subject: normalize robot.txt and specify test servers as scope of security audits X-Git-Tag: v1.0.0-beta.14~56 X-Git-Url: https://git.immae.eu/?a=commitdiff_plain;h=df182b373fc49f20188d531494e1bff1a9ad247e;p=github%2FChocobozzz%2FPeerTube.git normalize robot.txt and specify test servers as scope of security audits --- diff --git a/SECURITY.md b/SECURITY.md index 37ed19246..5c668a2a3 100644 --- a/SECURITY.md +++ b/SECURITY.md @@ -30,7 +30,7 @@ To encourage vulnerability research and to avoid any confusion between good-fait - Avoid violating the privacy of others, disrupting our systems, destroying data, and/or harming user experience. - Use only the Official Channels to discuss vulnerability information with us. - Keep the details of any discovered vulnerabilities confidential until they are fixed, according to the Disclosure Terms in this policy. -- Perform testing only on in-scope systems, and respect systems and activities which are out-of-scope. +- Perform testing only on in-scope systems, and respect systems and activities which are out-of-scope. Systems currently considered in-scope are the official demonstration/test servers provided by the PeerTube development team. - If a vulnerability provides unintended access to data: Limit the amount of data you access to the minimum required for effectively demonstrating a Proof of Concept; and cease testing and submit a report immediately if you encounter any user data during testing, such as Personally Identifiable Information (PII), Personal Healthcare Information (PHI), credit card data, or proprietary information. - You should only interact with test accounts you own or with explicit permission from the account holder. - Do not engage in extortion. diff --git a/config/default.yaml b/config/default.yaml index adac9deeb..ab07bfedd 100644 --- a/config/default.yaml +++ b/config/default.yaml @@ -142,7 +142,7 @@ instance: # Robot.txt rules. To disallow robots to crawl your instance and disallow indexation of your site, add '/' to "Disallow:' robots: | User-agent: * - Disallow: '' + Disallow: # Security.txt rules. To discourage researchers from testing your instance and disable security.txt integration, set this to an empty string. securitytxt: "# If you would like to report a security issue\n# you may report it to:\nContact: https://github.com/Chocobozzz/PeerTube/blob/develop/SECURITY.md\nContact: mailto:" diff --git a/config/production.yaml.example b/config/production.yaml.example index ca7b936c2..f9557b8eb 100644 --- a/config/production.yaml.example +++ b/config/production.yaml.example @@ -156,7 +156,7 @@ instance: # Robot.txt rules. To disallow robots to crawl your instance and disallow indexation of your site, add '/' to "Disallow:' robots: | User-agent: * - Disallow: '' + Disallow: # Security.txt rules. To discourage researchers from testing your instance and disable security.txt integration, set this to an empty string. securitytxt: "# If you would like to report a security issue\n# you may report it to:\nContact: https://github.com/Chocobozzz/PeerTube/blob/develop/SECURITY.md\nContact: mailto:"