feat: comprehensive registry improvements
Community docs: - CODE_OF_CONDUCT.md (Contributor Covenant v2.1) - SECURITY.md (vulnerability reporting policy) - CHANGELOG.md (initial release notes) - CODEOWNERS (per-type review ownership) GitHub config: - Issue templates: bug-report, pricing-correction, documentation - FUNDING.yml (GitHub Sponsors) Validation enhancements: - Cross-reference check: hand [[requires]] → integration existence - Routing alias collisions as warnings (errors with --strict) - --strict flag to promote warnings to errors - --type filter to validate single content type - CI: add taplo format check and lychee link check jobs Developer experience: - Makefile with validate, fmt, and scaffold targets - Scaffold templates for all 5 content types - .pre-commit-config.yaml (trailing whitespace, TOML check, validate) - docs/content-guide.md (naming, descriptions, prompts, decision guide) Content quality: - schema.toml: add last_verified field for model pricing - CONTRIBUTING.md: add pricing verification guide with source links
This commit is contained in:
1 parent
6cc5c745be
commit
a8b7c9d08b
20 files changed
+670
-18
No files matched your search
+34
@@ -0,0 +1,34 @@
|
||||
# Security Policy
|
||||
|
||||
## Scope
|
||||
|
||||
This repository contains TOML content definitions (agents, hands, integrations, skills, plugins, providers). Security concerns include:
|
||||
|
||||
- Malicious content in system prompts or descriptions
|
||||
- Command injection in integration transport commands
|
||||
- Integration URLs pointing to phishing or malicious sites
|
||||
- Credential exposure in TOML files
|
||||
|
||||
## Reporting a Vulnerability
|
||||
|
||||
**Do NOT open a public issue for security vulnerabilities.**
|
||||
|
||||
Email **security@librefang.dev** with:
|
||||
|
||||
1. Description of the vulnerability
|
||||
2. Affected file(s) and content type
|
||||
3. Steps to reproduce or exploit
|
||||
4. Suggested fix (if any)
|
||||
|
||||
## Response Timeline
|
||||
|
||||
- **Acknowledgment**: within 48 hours
|
||||
- **Assessment**: within 5 business days
|
||||
- **Fix**: dependent on severity, typically within 2 weeks
|
||||
|
||||
## Supported Versions
|
||||
|
||||
| Version | Supported |
|
||||
|---------|-----------|
|
||||
| main branch | Yes |
|
||||
| Other branches | No |
|
||||
Reference in new issue
Block a user