mirror of
https://github.com/MasterAcnolo/Freedom-Loader.git
synced 2026-07-29 10:15:47 +02:00
Fix: Security, Contributing, Code Of Conduct
This commit is contained in:
@@ -2,127 +2,110 @@
|
||||
|
||||
## Our Pledge
|
||||
|
||||
We as members, contributors, and leaders pledge to make participation in our
|
||||
community a harassment-free experience for everyone, regardless of age, body
|
||||
size, visible or invisible disability, ethnicity, sex characteristics, gender
|
||||
identity and expression, level of experience, education, socio-economic status,
|
||||
nationality, personal appearance, race, religion, or sexual identity
|
||||
and orientation.
|
||||
We as members, contributors, and leaders pledge to make participation in the Freedom Loader community a harassment-free experience for everyone, regardless of age, body size, visible or invisible disability, ethnicity, sex characteristics, gender identity and expression, level of experience, education, socio-economic status, nationality, personal appearance, race, religion, or sexual identity and orientation.
|
||||
|
||||
We pledge to act and interact in ways that contribute to an open, welcoming,
|
||||
diverse, inclusive, and healthy community.
|
||||
We pledge to act and interact in ways that contribute to an open, welcoming, diverse, inclusive, and healthy community.
|
||||
|
||||
## Our Standards
|
||||
|
||||
Examples of behavior that contributes to a positive environment for our
|
||||
community include:
|
||||
Examples of behavior that contributes to a positive environment for our community include:
|
||||
|
||||
* Demonstrating empathy and kindness toward other people
|
||||
* Being respectful of differing opinions, viewpoints, and experiences
|
||||
* Giving and gracefully accepting constructive feedback
|
||||
* Accepting responsibility and apologizing to those affected by our mistakes,
|
||||
and learning from the experience
|
||||
* Focusing on what is best not just for us as individuals, but for the
|
||||
overall community
|
||||
* Accepting responsibility and apologizing to those affected by our mistakes, and learning from the experience
|
||||
* Focusing on what is best not just for us as individuals, but for the overall community
|
||||
* Supporting fellow contributors and helping newcomers feel welcome
|
||||
|
||||
Examples of unacceptable behavior include:
|
||||
|
||||
* The use of sexualized language or imagery, and sexual attention or
|
||||
advances of any kind
|
||||
* The use of sexualized language or imagery, and sexual attention or advances of any kind
|
||||
* Trolling, insulting or derogatory comments, and personal or political attacks
|
||||
* Public or private harassment
|
||||
* Publishing others' private information, such as a physical or email
|
||||
address, without their explicit permission
|
||||
* Other conduct which could reasonably be considered inappropriate in a
|
||||
professional setting
|
||||
* Publishing others' private information, such as a physical or email address, without their explicit permission
|
||||
* Sustained disruption of discussions, issues, or pull requests
|
||||
* Other conduct which could reasonably be considered inappropriate in a professional setting
|
||||
|
||||
## Enforcement Responsibilities
|
||||
|
||||
Community leaders are responsible for clarifying and enforcing our standards of
|
||||
acceptable behavior and will take appropriate and fair corrective action in
|
||||
response to any behavior that they deem inappropriate, threatening, offensive,
|
||||
or harmful.
|
||||
Community leaders and project maintainers are responsible for clarifying and enforcing our standards of acceptable behavior and will take appropriate and fair corrective action in response to any behavior that they deem inappropriate, threatening, offensive, or harmful.
|
||||
|
||||
Community leaders have the right and responsibility to remove, edit, or reject
|
||||
comments, commits, code, wiki edits, issues, and other contributions that are
|
||||
not aligned to this Code of Conduct, and will communicate reasons for moderation
|
||||
decisions when appropriate.
|
||||
Community leaders have the right and responsibility to remove, edit, or reject comments, commits, code, wiki edits, issues, and other contributions that are not aligned to this Code of Conduct, and will communicate reasons for moderation decisions when appropriate.
|
||||
|
||||
## Scope
|
||||
|
||||
This Code of Conduct applies within all community spaces, and also applies when
|
||||
an individual is officially representing the community in public spaces.
|
||||
Examples of representing our community include using an official e-mail address,
|
||||
posting via an official social media account, or acting as an appointed
|
||||
representative at an online or offline event.
|
||||
This Code of Conduct applies within all community spaces, including:
|
||||
|
||||
- GitHub repository (issues, pull requests, discussions, wiki)
|
||||
- Project documentation and website
|
||||
- Official communication channels (Discord, email, etc.)
|
||||
- Social media accounts representing the project
|
||||
- Project events and meetings (online or offline)
|
||||
|
||||
This Code of Conduct also applies when an individual is officially representing the community in public spaces. Examples of representing our community include using an official email address, posting via an official social media account, or acting as an appointed representative at an online or offline event.
|
||||
|
||||
## Enforcement
|
||||
|
||||
Instances of abusive, harassing, or otherwise unacceptable behavior may be
|
||||
reported to the community leaders responsible for enforcement at
|
||||
masteracnolo25@gmail.com.
|
||||
Instances of abusive, harassing, or otherwise unacceptable behavior may be reported to the community leaders responsible for enforcement at **masteracnolo25@gmail.com**.
|
||||
|
||||
All complaints will be reviewed and investigated promptly and fairly.
|
||||
|
||||
All community leaders are obligated to respect the privacy and security of the
|
||||
reporter of any incident.
|
||||
All community leaders are obligated to respect the privacy and security of the reporter of any incident.
|
||||
|
||||
## Enforcement Guidelines
|
||||
|
||||
Community leaders will follow these Community Impact Guidelines in determining
|
||||
the consequences for any action they deem in violation of this Code of Conduct:
|
||||
Community leaders will follow these Community Impact Guidelines in determining the consequences for any action they deem in violation of this Code of Conduct:
|
||||
|
||||
### 1. Correction
|
||||
|
||||
**Community Impact**: Use of inappropriate language or other behavior deemed
|
||||
unprofessional or unwelcome in the community.
|
||||
**Community Impact**: Use of inappropriate language or other behavior deemed unprofessional or unwelcome in the community.
|
||||
|
||||
**Consequence**: A private, written warning from community leaders, providing
|
||||
clarity around the nature of the violation and an explanation of why the
|
||||
behavior was inappropriate. A public apology may be requested.
|
||||
**Consequence**: A private, written warning from community leaders, providing clarity around the nature of the violation and an explanation of why the behavior was inappropriate. A public apology may be requested.
|
||||
|
||||
### 2. Warning
|
||||
|
||||
**Community Impact**: A violation through a single incident or series
|
||||
of actions.
|
||||
**Community Impact**: A violation through a single incident or series of actions.
|
||||
|
||||
**Consequence**: A warning with consequences for continued behavior. No
|
||||
interaction with the people involved, including unsolicited interaction with
|
||||
those enforcing the Code of Conduct, for a specified period of time. This
|
||||
includes avoiding interactions in community spaces as well as external channels
|
||||
like social media. Violating these terms may lead to a temporary or
|
||||
permanent ban.
|
||||
**Consequence**: A warning with consequences for continued behavior. No interaction with the people involved, including unsolicited interaction with those enforcing the Code of Conduct, for a specified period of time. This includes avoiding interactions in community spaces as well as external channels like social media. Violating these terms may lead to a temporary or permanent ban.
|
||||
|
||||
### 3. Temporary Ban
|
||||
|
||||
**Community Impact**: A serious violation of community standards, including
|
||||
sustained inappropriate behavior.
|
||||
**Community Impact**: A serious violation of community standards, including sustained inappropriate behavior.
|
||||
|
||||
**Consequence**: A temporary ban from any sort of interaction or public
|
||||
communication with the community for a specified period of time. No public or
|
||||
private interaction with the people involved, including unsolicited interaction
|
||||
with those enforcing the Code of Conduct, is allowed during this period.
|
||||
Violating these terms may lead to a permanent ban.
|
||||
**Consequence**: A temporary ban from any sort of interaction or public communication with the community for a specified period of time. No public or private interaction with the people involved, including unsolicited interaction with those enforcing the Code of Conduct, is allowed during this period. Violating these terms may lead to a permanent ban.
|
||||
|
||||
### 4. Permanent Ban
|
||||
|
||||
**Community Impact**: Demonstrating a pattern of violation of community
|
||||
standards, including sustained inappropriate behavior, harassment of an
|
||||
individual, or aggression toward or disparagement of classes of individuals.
|
||||
**Community Impact**: Demonstrating a pattern of violation of community standards, including sustained inappropriate behavior, harassment of an individual, or aggression toward or disparagement of classes of individuals.
|
||||
|
||||
**Consequence**: A permanent ban from any sort of public interaction within
|
||||
the community.
|
||||
**Consequence**: A permanent ban from any sort of public interaction within the community.
|
||||
|
||||
## Our Commitment to Contributors
|
||||
|
||||
At Freedom Loader, we value every contribution—whether it's a bug report, feature suggestion, code improvement, or documentation fix. We strive to:
|
||||
|
||||
- Respond to issues and pull requests in a timely manner
|
||||
- Provide constructive feedback on contributions
|
||||
- Help new contributors get started
|
||||
- Maintain a welcoming environment for all skill levels
|
||||
- Credit contributors appropriately for their work
|
||||
|
||||
## Questions and Clarifications
|
||||
|
||||
If you have questions about this Code of Conduct or need clarification on what constitutes acceptable behavior, please:
|
||||
|
||||
- Open a [discussion](https://github.com/MasterAcnolo/Freedom-Loader/discussions) on GitHub
|
||||
- Contact the maintainers at masteracnolo25@gmail.com
|
||||
- Review the [Contributing Guidelines](CONTRIBUTING.md)
|
||||
|
||||
## Attribution
|
||||
|
||||
This Code of Conduct is adapted from the [Contributor Covenant][homepage],
|
||||
version 2.0, available at
|
||||
https://www.contributor-covenant.org/version/2/0/code_of_conduct.html.
|
||||
This Code of Conduct is adapted from the [Contributor Covenant](https://www.contributor-covenant.org), version 2.0, available at https://www.contributor-covenant.org/version/2/0/code_of_conduct.html.
|
||||
|
||||
Community Impact Guidelines were inspired by [Mozilla's code of conduct
|
||||
enforcement ladder](https://github.com/mozilla/diversity).
|
||||
Community Impact Guidelines were inspired by [Mozilla's code of conduct enforcement ladder](https://github.com/mozilla/diversity).
|
||||
|
||||
[homepage]: https://www.contributor-covenant.org
|
||||
For answers to common questions about this code of conduct, see the FAQ at https://www.contributor-covenant.org/faq. Translations are available at https://www.contributor-covenant.org/translations.
|
||||
|
||||
For answers to common questions about this code of conduct, see the FAQ at
|
||||
https://www.contributor-covenant.org/faq. Translations are available at
|
||||
https://www.contributor-covenant.org/translations.
|
||||
---
|
||||
|
||||
**Remember**: Freedom Loader is built by people who care. Let's keep this community a place where everyone feels welcome to contribute.
|
||||
176
CONTRIBUTING.md
176
CONTRIBUTING.md
@@ -1,66 +1,164 @@
|
||||
# Contributing to Freedom Loader
|
||||
|
||||
Welcome! Thanks for being interested in Freedom Loader. Your contributions-bug reports, feature ideas, or code improvements-are always appreciated. Every contribution makes Freedom Loader better 💪
|
||||
Welcome! Thanks for your interest in Freedom Loader. Your contributions—bug reports, feature ideas, or code improvements—are always appreciated. Every contribution makes Freedom Loader better.
|
||||
|
||||
---
|
||||
|
||||
## 1. Check Before Contributing
|
||||
- Make sure your issue, bug, or feature request doesn't already exist.
|
||||
- Search issues and pull requests before creating a new one.
|
||||
- Follow the [Code of Conduct](CODE_OF_CONDUCT.md).
|
||||
## Quick Links
|
||||
|
||||
- [Code of Conduct](CODE_OF_CONDUCT.md)
|
||||
- [Issue Templates](.github/ISSUE_TEMPLATE/)
|
||||
- [Pull Request Templates](.github/PULL_REQUEST_TEMPLATE/)
|
||||
- [Security Policy](SECURITY.md)
|
||||
|
||||
---
|
||||
|
||||
## 2. Report an Issue
|
||||
Found a bug, weird behavior, or have an idea? Open an [**issue**](https://github.com/MasterAcnolo/Freedom-Loader/issues) using the **Bug Report template**.
|
||||
Make sure to include:
|
||||
- Steps to reproduce the issue
|
||||
- App version and environment (OS, Node, Browser, etc.)
|
||||
- Logs if possible: `C:\Users\[USERNAME]\AppData\Local\FreedomLoader\logs\LOGS-20xx-xx-xx.log`
|
||||
- Screenshots if relevant
|
||||
## Ways to Contribute
|
||||
|
||||
### 1. Report a Bug
|
||||
|
||||
Found a bug or unexpected behavior? Open an [**issue**](https://github.com/MasterAcnolo/Freedom-Loader/issues) using the **Bug Report** template.
|
||||
|
||||
**Please include:**
|
||||
- Clear description of the bug
|
||||
- Steps to reproduce
|
||||
- App version and environment (Windows version, Firefox version if relevant)
|
||||
- Logs from: `C:\Users\[USERNAME]\AppData\Local\FreedomLoader\logs\LOGS-YYYY-MM-DD.log`
|
||||
- Screenshots if applicable
|
||||
|
||||
### 2. Request a Feature
|
||||
|
||||
Have an idea to improve Freedom Loader? Open a [**Feature Request**](https://github.com/MasterAcnolo/Freedom-Loader/issues/new/choose).
|
||||
|
||||
**Tips:**
|
||||
- Describe the problem it solves
|
||||
- Explain your proposed solution
|
||||
- Include use cases and examples
|
||||
|
||||
### 3. Submit Code Changes
|
||||
|
||||
**Before starting:**
|
||||
- Check existing issues and PRs to avoid duplicates
|
||||
- For major changes, open an issue first to discuss
|
||||
- Follow the project's code style and conventions
|
||||
|
||||
**Process:**
|
||||
1. Fork the repository
|
||||
2. Create a feature branch: `git checkout -b feature/your-feature-name`
|
||||
3. Make your changes
|
||||
4. Test thoroughly on Windows 10/11
|
||||
5. Commit with clear messages: `git commit -m "Add feature X"`
|
||||
6. Push to your fork: `git push origin feature/your-feature-name`
|
||||
7. Open a Pull Request using the appropriate template
|
||||
|
||||
**Code Guidelines:**
|
||||
- Use camelCase for variables and functions
|
||||
- Comment complex logic
|
||||
- Keep commits focused and atomic
|
||||
- Update documentation if needed
|
||||
- Don't modify version numbers (done during release)
|
||||
|
||||
### 4. Improve Documentation
|
||||
|
||||
Documentation improvements are always welcome:
|
||||
- Fix typos or unclear sections
|
||||
- Add missing examples
|
||||
- Update outdated information
|
||||
- Improve README, wiki, or guides
|
||||
|
||||
Small contributions matter—don't hesitate to submit documentation PRs.
|
||||
|
||||
---
|
||||
|
||||
## 3. Submit a Pull Request
|
||||
To fix a bug, add a feature, or improve docs:
|
||||
1. Fork the repository
|
||||
2. Create a branch: `git checkout -b feature/my-awesome-feature`
|
||||
3. Make your changes
|
||||
4. Add tests or verification steps
|
||||
5. Test everything locally
|
||||
6. Open a PR to the `main` branch
|
||||
## Development Setup
|
||||
|
||||
**Tips for PRs:**
|
||||
- Keep titles and descriptions clear and concise
|
||||
- Document what you change and why
|
||||
- Follow existing code style (camelCase for variables/functions)
|
||||
- Small commits focused on a single purpose are easier to review
|
||||
### Prerequisites
|
||||
- Node.js 16.x or higher
|
||||
- npm or yarn
|
||||
- Git
|
||||
- Windows 10/11 (for testing)
|
||||
|
||||
### Setup
|
||||
```bash
|
||||
# Clone your fork
|
||||
git clone https://github.com/YOUR-USERNAME/Freedom-Loader.git
|
||||
cd Freedom-Loader
|
||||
|
||||
# Install dependencies
|
||||
npm install
|
||||
|
||||
# Run in development mode
|
||||
npm start
|
||||
|
||||
# Build for production
|
||||
npm run build
|
||||
```
|
||||
|
||||
### Project Structure
|
||||
```
|
||||
Freedom-Loader/
|
||||
├── main.js # Electron main process
|
||||
├── preload.js # Electron preload script
|
||||
├── config.js # Global configuration
|
||||
├── server/ # Express backend
|
||||
│ ├── routes/ # API routes
|
||||
│ ├── controller/ # Business logic
|
||||
│ └── helpers/ # Utility functions
|
||||
├── public/ # Frontend (HTML, CSS, JS)
|
||||
└── ressources/ # Binaries (yt-dlp, ffmpeg, etc.)
|
||||
```
|
||||
|
||||
---
|
||||
|
||||
## 4. Improve the Documentation
|
||||
Docs are important: README, wiki, guides… If something is unclear, improve it!
|
||||
Small contributions like fixing typos or adding examples are always welcome.
|
||||
## Testing
|
||||
|
||||
Before submitting a PR, verify:
|
||||
- [ ] Download functionality works (video/audio)
|
||||
- [ ] Playlist downloads work
|
||||
- [ ] Settings panel functions correctly
|
||||
- [ ] Custom path selection works
|
||||
- [ ] No errors in application logs
|
||||
- [ ] UI changes work on all themes (if applicable)
|
||||
- [ ] Tested on Windows 10 and/or Windows 11
|
||||
|
||||
---
|
||||
|
||||
## 5. Testing & Verification
|
||||
- Test new features thoroughly
|
||||
- Ensure bug fixes actually fix the reported issue
|
||||
- Include any relevant logs or screenshots
|
||||
## Pull Request Review Process
|
||||
|
||||
1. **Submission**: Open PR with clear description using the template
|
||||
2. **Review**: Maintainers review code and provide feedback
|
||||
3. **Updates**: Address feedback and push updates
|
||||
4. **Approval**: Once approved, PR will be merged
|
||||
5. **Release**: Changes included in next release
|
||||
|
||||
**Response times:**
|
||||
- Bug fixes: Usually reviewed within 2-3 days
|
||||
- Features: May take longer depending on complexity
|
||||
- Documentation: Often reviewed quickly
|
||||
|
||||
---
|
||||
|
||||
## 6. Review & Merge
|
||||
- After submitting a PR, it will be reviewed by maintainers
|
||||
- Be open to feedback and changes
|
||||
- We try to respond quickly, but sometimes have other priorities
|
||||
## Code of Conduct
|
||||
|
||||
Be respectful and constructive in all interactions. We welcome everyone as long as discussions remain polite and productive.
|
||||
|
||||
See [CODE_OF_CONDUCT.md](CODE_OF_CONDUCT.md) for details.
|
||||
|
||||
---
|
||||
|
||||
## 7. Code of Conduct
|
||||
Please contribute respectfully and constructively. Everyone is welcome as long as discussions remain polite and productive.
|
||||
## Questions?
|
||||
|
||||
- Check the [FAQ](https://masteracnolo.github.io/FreedomLoader/pages/faq.html)
|
||||
- Review the [Wiki](https://masteracnolo.github.io/FreedomLoader/pages/wiki.html)
|
||||
- Open a [Question issue](https://github.com/MasterAcnolo/Freedom-Loader/issues/new/choose)
|
||||
|
||||
---
|
||||
|
||||
Thanks to Zakaria for the website icon. Check him out here: [IG Link](https://www.instagram.com/designmark_studio/) 🔥
|
||||
## Credits
|
||||
|
||||
Thanks to **Zakaria** for the website icon design.
|
||||
Check out his work: [IG @designmark_studio](https://www.instagram.com/designmark_studio/)
|
||||
|
||||
---
|
||||
|
||||
**Thank you for contributing to Freedom Loader!**
|
||||
168
SECURITY.md
168
SECURITY.md
@@ -2,39 +2,157 @@
|
||||
|
||||
## Supported Versions
|
||||
|
||||
We actively maintain security updates for the following versions (Since the 1.3.0 the application auto-update, patch will be apply easily):
|
||||
We actively maintain and provide security updates for the following versions of Freedom Loader:
|
||||
|
||||
| Version | Supported |
|
||||
| -------- | ----------------- |
|
||||
| 1.3.x | :white_check_mark: |
|
||||
| 1.2.x | :white_check_mark: |
|
||||
| 1.1.x | :white_check_mark:|
|
||||
| <1.1 | :white_check_mark: |
|
||||
| Version | Supported |
|
||||
| ------- | ------------------ |
|
||||
| 1.4.x | :white_check_mark: |
|
||||
| 1.3.x | :white_check_mark: |
|
||||
| < 1.3.0 | :x: |
|
||||
|
||||
> Only versions marked with ✅ receive security updates. Older versions may be vulnerable.
|
||||
|
||||
---
|
||||
**Note**: We recommend always using the latest version to benefit from the most recent security patches and features.
|
||||
|
||||
## Reporting a Vulnerability
|
||||
|
||||
If you discover a security vulnerability in Freedom Loader, **do not create a public issue**. Report it privately:
|
||||
If you discover a security vulnerability in Freedom Loader, please help us keep the project and its users safe by reporting it responsibly.
|
||||
|
||||
- Email: **masteracnolo25@gmail.com**
|
||||
- Include:
|
||||
- Description of the vulnerability
|
||||
- Steps to reproduce it
|
||||
- App version and environment (OS, Node, Browser if relevant)
|
||||
- Logs or screenshots if possible (`C:\Users\[USERNAME]\AppData\Local\FreedomLoader\logs\LOGS-20xx-xx-xx.log`)
|
||||
### How to Report
|
||||
|
||||
We will respond as quickly as possible, typically within **48 hours**, and keep you updated on the fix.
|
||||
**DO NOT** open a public issue for security vulnerabilities.
|
||||
|
||||
We may acknowledge responsible disclosures in release notes unless you request anonymity.
|
||||
Instead, please report security issues privately by:
|
||||
|
||||
1. **Email**: Send details to **masteracnolo25@gmail.com** with the subject line: `[SECURITY] Vulnerability Report`
|
||||
2. **Include**:
|
||||
- Description of the vulnerability
|
||||
- Steps to reproduce the issue
|
||||
- Potential impact and severity
|
||||
- Suggested fix (if available)
|
||||
- Your contact information for follow-up
|
||||
|
||||
### What to Expect
|
||||
|
||||
- **Acknowledgment**: We will acknowledge receipt of your report within 48 hours
|
||||
- **Assessment**: We will assess the vulnerability and determine its severity
|
||||
- **Updates**: We will keep you informed of our progress
|
||||
- **Resolution**: We aim to release a fix within 7-14 days for critical vulnerabilities
|
||||
- **Credit**: We will credit you in the release notes (unless you prefer to remain anonymous)
|
||||
|
||||
## Security Best Practices for Users
|
||||
|
||||
When using Freedom Loader, we recommend:
|
||||
|
||||
### General Security
|
||||
|
||||
- **Keep Updated**: Always use the latest version of Freedom Loader
|
||||
- **Official Sources**: Download only from official releases on [GitHub](https://github.com/MasterAcnolo/Freedom-Loader/releases)
|
||||
- **Verify Downloads**: Check that installers are properly signed (Windows SmartScreen may show warnings for new releases)
|
||||
- **Antivirus**: Keep your antivirus software up to date
|
||||
|
||||
### Configuration Security
|
||||
|
||||
- **Download Path**: Only set download paths within your user directory (`C:\Users\[USERNAME]\...`)
|
||||
- **Cookies**: Be aware that Firefox cookies are used for authentication—keep Firefox secure
|
||||
- **Logs**: Logs may contain sensitive information—avoid sharing them publicly without review
|
||||
|
||||
### Privacy Considerations
|
||||
|
||||
Freedom Loader respects your privacy:
|
||||
|
||||
- **No Data Collection**: We don't collect, store, or transmit your personal data
|
||||
- **No Telemetry**: No usage tracking or analytics
|
||||
- **Local Operation**: All downloads are processed locally on your machine
|
||||
- **Optional Features**: Discord RPC is optional and can be disabled
|
||||
|
||||
## Known Security Considerations
|
||||
|
||||
### Browser Cookie Access
|
||||
|
||||
Freedom Loader accesses Firefox cookies to download protected content. This is:
|
||||
|
||||
- **By Design**: Required for age-restricted or member-only content
|
||||
- **Local Only**: Cookies are read locally and never transmitted
|
||||
- **User Controlled**: You can control what content you download
|
||||
|
||||
### Native Dependencies
|
||||
|
||||
Freedom Loader bundles native binaries:
|
||||
|
||||
- **yt-dlp**: Official builds from [yt-dlp/yt-dlp](https://github.com/yt-dlp/yt-dlp)
|
||||
- **FFmpeg**: Official builds from [FFmpeg.org](https://ffmpeg.org/)
|
||||
- **Deno**: Official builds from [Deno.land](https://deno.land/)
|
||||
|
||||
These dependencies are verified and updated regularly.
|
||||
|
||||
### Windows Defender Warnings
|
||||
|
||||
New releases may trigger Windows Defender warnings because:
|
||||
|
||||
- The application is not yet widely distributed
|
||||
- Code signing certificates are expensive for open-source projects
|
||||
|
||||
This is expected behavior for new releases. The warning will decrease as more users download the software.
|
||||
|
||||
## Vulnerability Disclosure Policy
|
||||
|
||||
### Our Commitment
|
||||
|
||||
We are committed to:
|
||||
|
||||
- Responding promptly to security reports
|
||||
- Working with security researchers to verify and address issues
|
||||
- Keeping users informed about security updates
|
||||
- Crediting researchers who report vulnerabilities responsibly
|
||||
|
||||
### Disclosure Timeline
|
||||
|
||||
1. **Day 0**: Vulnerability reported privately
|
||||
2. **Day 1-2**: Acknowledgment sent to reporter
|
||||
3. **Day 3-7**: Vulnerability assessed and fix developed
|
||||
4. **Day 7-14**: Fix released (critical vulnerabilities prioritized)
|
||||
5. **Day 14+**: Public disclosure (coordinated with reporter)
|
||||
|
||||
### Scope
|
||||
|
||||
Security issues we're most interested in:
|
||||
|
||||
- **Code Execution**: Arbitrary code execution vulnerabilities
|
||||
- **Path Traversal**: Issues with file system access controls
|
||||
- **Injection**: Command injection or similar vulnerabilities
|
||||
- **Authentication**: Bypass of security controls
|
||||
- **Data Exposure**: Unintended exposure of sensitive data
|
||||
|
||||
### Out of Scope
|
||||
|
||||
The following are generally not considered security vulnerabilities:
|
||||
|
||||
- Issues requiring physical access to the user's machine
|
||||
- Social engineering attacks
|
||||
- Denial of service against third-party services
|
||||
- Issues in third-party dependencies (report to upstream projects)
|
||||
- Missing security headers on local HTTP server (no remote access)
|
||||
|
||||
## Security Updates
|
||||
|
||||
Security updates are released as:
|
||||
|
||||
- **Patch Releases**: For critical security fixes (e.g., 1.4.1 → 1.4.2)
|
||||
- **Automatic Updates**: Users are notified via the built-in update system
|
||||
- **Release Notes**: Security fixes are clearly marked in changelog
|
||||
|
||||
## Additional Resources
|
||||
|
||||
- [Contributing Guidelines](CONTRIBUTING.md)
|
||||
- [Code of Conduct](CODE_OF_CONDUCT.md)
|
||||
- [GitHub Security Advisories](https://github.com/MasterAcnolo/Freedom-Loader/security/advisories)
|
||||
|
||||
## Contact
|
||||
|
||||
For security-related questions or concerns:
|
||||
|
||||
- **Email**: masteracnolo25@gmail.com (Subject: [SECURITY])
|
||||
- **GitHub**: [@MasterAcnolo](https://github.com/MasterAcnolo)
|
||||
|
||||
---
|
||||
|
||||
## What Happens Next
|
||||
|
||||
- We will confirm receipt of your report
|
||||
- Investigate and reproduce the issue
|
||||
- Deploy a fix and release an update
|
||||
- Notify you when the fix is live
|
||||
**Thank you for helping keep Freedom Loader and its users safe!**
|
||||
Reference in New Issue
Block a user