SECURITY.md

Security Policy

WebholeInk is designed to be secure by architecture, not by add-ons.

There is:

Security vulnerabilities are therefore limited in scope by design.


Supported Versions

Only the latest release on main is supported.

WebholeInk does not provide security backports for older versions.

Version Supported
v0.x โœ… Yes (latest only)
< v0.x โŒ No

Threat Model

WebholeInk assumes:

This project is not intended for:

If you need those features, this is the wrong tool.


Built-In Protections

Architecture

HTTP Security

Content Handling

Caching Safety


Reporting a Vulnerability

If you believe you have found a security issue:

  1. Do not open a public issue
  2. Do not disclose the issue publicly

Instead, contact:

๐Ÿ“ง security@cliffordswebhole.com

Please include:

You will receive an acknowledgment within 72 hours.


Disclosure Policy


Non-Goals

The following are explicitly out of scope:


Final Notes

WebholeInk favors:

If a feature increases attack surface without improving reliability, it will not be accepted.

Security is a property of simplicity.