From a1bf5f92d1d38eaa36af90d48765bd1765620e6b Mon Sep 17 00:00:00 2001 From: theMackabu Date: Sat, 7 Feb 2026 02:19:28 -0800 Subject: [PATCH] add security policy and contributing guidelines --- CONTRIBUTING.md | 73 +++++++++++++++++++++++++++++++++++++++++++++++++ README.md | 12 +++++++- SECURITY.md | 43 +++++++++++++++++++++++++++++ 3 files changed, 127 insertions(+), 1 deletion(-) create mode 100644 CONTRIBUTING.md create mode 100644 SECURITY.md diff --git a/CONTRIBUTING.md b/CONTRIBUTING.md new file mode 100644 index 0000000..78a5e03 --- /dev/null +++ b/CONTRIBUTING.md @@ -0,0 +1,73 @@ +# Contributing to Ant + +Thank you for your interest in contributing to Ant! This document provides guidelines for contributing. + +## Getting Started + +### Prerequisites + +- C compiler with C23 support (GCC 14+ or Clang 18+) +- Meson build system +- Git +- OpenSSL +- libSodium + +### Building from Source + +```bash +git clone https://github.com/theMackabu/ant.git && cd ant + +meson subprojects download +meson setup build +meson compile -C build +``` + +## How to Contribute + +### Reporting Bugs + +1. Check existing issues first +2. Include reproduction steps +3. Provide system info (OS, compiler version) +4. Include relevant error messages + +### Suggesting Features + +1. Open an issue with the `enhancement` label +2. Describe the use case +3. Provide examples if possible + +### Pull Requests + +1. Fork the repository +2. Create a feature branch (`git checkout -b feature/my-feature`) +3. Make your changes +4. Ensure tests pass +5. Submit a pull request + +## Code Style + +- **C code**: GNU23 standard, 2-space indent, no trailing whitespace +- **Naming**: `snake_case` for functions, `UPPERCASE` for macros +- **Headers**: Local includes (`"..."`) before system includes (`<...>`) +- **Comments**: Avoid unless code is complex + +## Project Structure + +``` +src/ +├── cli/ # Command line interface helpers +├── core/ # Bundled snapshot code +├── modules/ # Built-in JS modules (fs, path, shell, etc.) +├── esm/ # ES module system +├── pkg/ # Zig-based package manager +include/ # C header files +tests/ # JavaScript test files +vendor/ # External dependencies +``` + +## Testing + +- Add tests for new features in `tests/` +- Run specific tests: `./build/ant tests/test_.js` +- Run `./build/ant examples/spec/run.js` to ensure nothing else broke diff --git a/README.md b/README.md index 5bb422d..59f2b7f 100644 --- a/README.md +++ b/README.md @@ -16,12 +16,22 @@ curl -fsSL https://ant.themackabu.com/install | bash curl -fsSL https://ant.themackabu.com/install | MBEDTLS=1 bash ``` -## Build from source +### Building from Source ```bash +git clone https://github.com/theMackabu/ant.git && cd ant + meson subprojects download meson setup build meson compile -C build ``` +### Security + +For information on reporting security vulnerabilities in Ant, see [SECURITY.md](SECURITY.md). + +### Contributing to Ant + +We welcome contributions through pull request. See [CONTRIBUTING.md](CONTRIBUTING.md) for more details. + For more information about the internals, read the [ant deepwiki](https://deepwiki.com/theMackabu/ant). diff --git a/SECURITY.md b/SECURITY.md new file mode 100644 index 0000000..ef0609f --- /dev/null +++ b/SECURITY.md @@ -0,0 +1,43 @@ +# Security Policy + +## Supported Versions + +| Version | Supported | +| -------- | --------- | +| latest | ✅ | +| pre v0.5 | ❌ | + +## Reporting a Vulnerability + +If you discover a security vulnerability in Ant, please report it responsibly: + +1. **Do not** open a public GitHub issue +2. Email security concerns to: **themackabu@gmail.com** +3. Include: + - Description of the vulnerability + - Steps to reproduce + - Potential impact + - Any suggested fixes (optional) + +## Response Timeline + +- **Acknowledgment**: Within 12 hours +- **Initial assessment**: Within 2 days +- **Fix timeline**: Depends on severity (critical issues prioritized) + +## Security Considerations + +Ant is a JavaScript runtime with system-level access. When using Ant: + +- **FFI**: The `ant:ffi` module provides direct memory access. Only load trusted native libraries. +- **Shell execution**: The `ant:shell` module executes system commands. Sanitize all user input. +- **URL imports**: Remote module imports execute code from external sources. Only import from trusted origins. +- **File system**: The `ant:fs` module has full filesystem access. Validate paths carefully. + +## Disclosure Policy + +Once a vulnerability is fixed, we will: + +1. Release a patched version +2. Credit the reporter (if desired) +3. Publish a security advisory on GitHub -- 2.51.2