diff --git a/CONTRIBUTING.md b/CONTRIBUTING.md index b0c1dfc1..1b8146b3 100644 --- a/CONTRIBUTING.md +++ b/CONTRIBUTING.md @@ -13,7 +13,7 @@ 2. 克隆你的 Fork,并添加上游(便于同步): ```text - git remote add upstream https://github.com/<原仓库>/oclaw.git + git remote add upstream https://github.com/hansjone/oclaw.git ``` 3. 从 `main` 拉最新,并创建功能分支(命名清晰,如 `fix/...`、`feat/...`): diff --git a/LICENSE b/LICENSE new file mode 100644 index 00000000..ee914520 --- /dev/null +++ b/LICENSE @@ -0,0 +1,21 @@ +MIT License + +Copyright (c) 2026 hansjone and contributors + +Permission is hereby granted, free of charge, to any person obtaining a copy +of this software and associated documentation files (the "Software"), to deal +in the Software without restriction, including without limitation the rights +to use, copy, modify, merge, publish, distribute, sublicense, and/or sell +copies of the Software, and to permit persons to whom the Software is +furnished to do so, subject to the following conditions: + +The above copyright notice and this permission notice shall be included in all +copies or substantial portions of the Software. + +THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR +IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, +FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE +AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER +LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, +OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE +SOFTWARE. diff --git a/README.md b/README.md index e249e63d..e2eb4c5f 100644 --- a/README.md +++ b/README.md @@ -153,3 +153,8 @@ Chinese zero-to-running checklist: see **开箱即用(从零跑起来)** at See `docs/ENVIRONMENT_VARIABLES.md` for full runtime variable reference. +## License and security + +- License: [MIT](LICENSE). Third-party subtrees may carry their own license files; those terms apply to the respective files only. +- Vulnerability reporting: [SECURITY.md](SECURITY.md). + diff --git a/SECURITY.md b/SECURITY.md new file mode 100644 index 00000000..9044ae1f --- /dev/null +++ b/SECURITY.md @@ -0,0 +1,21 @@ +# Security policy + +## Supported versions + +Security fixes are applied on the default branch (`main`) when practical. Use the latest commit for deployments. + +## Reporting a vulnerability + +Please **do not** open a public GitHub issue for undisclosed security problems. + +Use **GitHub private vulnerability reporting** for this repository: + +[Submit a private security advisory](https://github.com/hansjone/oclaw/security/advisories/new) + +Include: + +- A short description of the impact +- Steps to reproduce (or proof-of-concept) if you can share them safely +- Affected component or path (if known) + +We will treat reports as confidential and coordinate a fix and disclosure timeline with you when possible.