diff --git a/.github/PULL_REQUEST_TEMPLATE.md b/.github/PULL_REQUEST_TEMPLATE.md new file mode 100644 index 0000000..d73b25c --- /dev/null +++ b/.github/PULL_REQUEST_TEMPLATE.md @@ -0,0 +1,19 @@ +## Summary + + +## Testing + +- [ ] Build succeeds (`go build .` from `src/`, not naming `ZeeCrypt.go` directly) +- [ ] Encrypt → decrypt round-trip: normal mode +- [ ] Encrypt → decrypt round-trip: paranoid mode +- [ ] Encrypt → decrypt round-trip: keyfiles (ordered and unordered) +- [ ] Encrypt → decrypt round-trip: deniability +- [ ] Encrypt → decrypt round-trip: Reed-Solomon +- [ ] Encrypt → decrypt round-trip: split/recombine +- [ ] Wrong password on decrypt still fails as expected +- [ ] Not applicable (docs/CI/packaging-only change) + +## Breaking changes + diff --git a/CODE_OF_CONDUCT.md b/CODE_OF_CONDUCT.md new file mode 100644 index 0000000..eb82402 --- /dev/null +++ b/CODE_OF_CONDUCT.md @@ -0,0 +1,70 @@ +# Contributor Covenant Code of Conduct + +## Our Pledge + +We as members, contributors, and leaders pledge to make participation in our +community a harassment-free experience for everyone, regardless of age, body +size, visible or invisible disability, ethnicity, sex characteristics, gender +identity and expression, level of experience, education, socio-economic status, +nationality, personal appearance, race, religion, or sexual identity +and orientation. + +We pledge to act and interact in ways that contribute to an open, welcoming, +diverse, inclusive, and healthy community. + +## Our Standards + +Examples of behavior that contributes to a positive environment for our +community include: + +* Demonstrating empathy and kindness toward other people +* Being respectful of differing opinions, viewpoints, and experiences +* Giving and gracefully accepting constructive feedback +* Accepting responsibility and apologizing to those affected by our mistakes, + and learning from the experience +* Focusing on what is best not just for us as individuals, but for the + overall community + +Examples of unacceptable behavior include: + +* The use of sexualized language or imagery, and sexual attention or advances + of any kind +* Trolling, insulting or derogatory comments, and personal or political attacks +* Public or private harassment +* Publishing others' private information, such as a physical or email + address, without their explicit permission +* Other conduct which could reasonably be considered inappropriate in a + professional setting + +## Enforcement Responsibilities + +Project maintainers are responsible for clarifying and enforcing our standards +of acceptable behavior and will take appropriate and fair corrective action in +response to any behavior that they deem inappropriate, threatening, offensive, +or harmful. + +## Scope + +This Code of Conduct applies within all community spaces (issues, pull +requests, discussions) and also applies when an individual is officially +representing the community in public spaces. + +## Enforcement + +Instances of abusive, harassing, or otherwise unacceptable behavior may be +reported to the maintainer, [@TheZeekA](https://github.com/TheZeekA), by +contacting them directly on GitHub or via a private security advisory on this +repository. All complaints will be reviewed and investigated promptly and +fairly. + +All maintainers are obligated to respect the privacy and security of the +reporter of any incident. + +## Attribution + +This Code of Conduct is adapted from the [Contributor Covenant][homepage], +version 2.1, available at +[https://www.contributor-covenant.org/version/2/1/code_of_conduct.html][v2.1]. + +[homepage]: https://www.contributor-covenant.org +[v2.1]: https://www.contributor-covenant.org/version/2/1/code_of_conduct.html diff --git a/CONTRIBUTING.md b/CONTRIBUTING.md new file mode 100644 index 0000000..55d9ed7 --- /dev/null +++ b/CONTRIBUTING.md @@ -0,0 +1,41 @@ +# Contributing to ZeeCrypt + +Thanks for wanting to contribute! ZeeCrypt is actively maintained and open to bug reports, feature requests, and pull requests. + +## Before you start + +- For anything beyond a small fix, consider opening an issue first to discuss the change — this avoids wasted work if the approach needs adjusting. +- For security vulnerabilities, see [SECURITY.md](SECURITY.md) instead of opening a public issue or PR. +- Read the [Code of Conduct](CODE_OF_CONDUCT.md). + +## Building from source + +See [src/README.md](src/README.md) for full build instructions. In short: +``` +cd src +go build -ldflags="-s -w -H=windowsgui -extldflags=-static" . +``` +Note the `.` at the end rather than naming `ZeeCrypt.go` directly — Go only auto-links the `.syso` icon resource files when building the package as a whole. + +## Making changes + +This repo uses two long-lived branches: +- **`testing`** — active development. Push feature branches and open PRs against this. +- **`main`** — release branch. Protected: changes only land here via PR from `testing` (or a fix branch), typically once a batch of work on `testing` is ready to ship. + +Workflow for a change: +1. Branch off `testing` +2. Make your change, and if you touch the encryption/decryption code, actually build and round-trip test it (encrypt then decrypt) — normal mode, paranoid mode, keyfiles, deniability, Reed-Solomon, and split/recombine as relevant to your change. This is cryptographic software; a change that looks correct but silently breaks decryption is worse than no change at all. +3. Open a PR into `testing` +4. Once merged, a maintainer will fold `testing` into `main` via a separate PR when it's ready for release + +## Reporting bugs + +Please include: +- ZeeCrypt version (shown in the window title) +- Steps to reproduce +- What you expected vs. what happened + +## Style + +This is a single-file Go application (`src/ZeeCrypt.go`). Match the existing style — run `gofmt` before committing. There's no test suite; changes to the cryptographic code path need to be manually verified by actually building and round-tripping real files (see above), since it can't be validated by reading the diff alone. diff --git a/README.md b/README.md index 6f1f12e..bb33611 100644 --- a/README.md +++ b/README.md @@ -2,7 +2,7 @@ ZeeCrypt is a very small, very simple, yet very secure encryption tool that you can use to protect your files. It's a Windows-only fork of [Picocrypt](https://github.com/Picocrypt/Picocrypt), designed to be the go-to tool for file encryption, with a focus on security, simplicity, and reliability. ZeeCrypt uses the secure XChaCha20 cipher and the Argon2id key derivation function to provide a high level of security. -🚀 **This repo is actively maintained.** Unlike the original (now-archived) Picocrypt, ZeeCrypt is under active development — bug reports, feature requests, and suggestions are welcome, so feel free to open an issue. +🚀 **This repo is actively maintained.** Unlike the original (now-archived) Picocrypt, ZeeCrypt is under active development — bug reports, feature requests, and suggestions are welcome, so feel free to open an issue. See [CONTRIBUTING.md](CONTRIBUTING.md) if you'd like to contribute code, and [SECURITY.md](SECURITY.md) to report a vulnerability.

ZeeCrypt

diff --git a/SECURITY.md b/SECURITY.md new file mode 100644 index 0000000..6af424c --- /dev/null +++ b/SECURITY.md @@ -0,0 +1,29 @@ +# Security Policy + +## Supported Versions + +Only the latest released version of ZeeCrypt is supported with security fixes. Older versions, and volumes encrypted with them, may not be compatible with the latest release — see [Changelog.md](Changelog.md) for breaking changes between versions. + +## Reporting a Vulnerability + +**Please do not open a public GitHub issue for security vulnerabilities.** + +Instead, use GitHub's private vulnerability reporting for this repository: + +1. Go to the [Security tab](https://github.com/TheZeekA/ZeeCrypt/security) +2. Click **Report a vulnerability** + +This opens a private conversation with the maintainer that isn't visible to the public until it's resolved. + +If you'd rather not use GitHub's reporting tool, you can contact [@TheZeekA](https://github.com/TheZeekA) directly. + +Please include: +- A description of the vulnerability and its potential impact +- Steps to reproduce it, or a proof of concept if possible +- The version of ZeeCrypt affected + +You should expect an initial response within a few days. There's no bug bounty program, but you'll be credited (if you'd like) once a fix is released. + +## Scope + +ZeeCrypt is designed for the offline security of encrypted volumes and assumes the host machine it runs on is trusted — see the [Security section of the README](README.md#security) and [Internals.md](Internals.md) for the threat model and known limitations (including PCC-004, an already-documented low-severity issue). Reports about that specific documented limitation don't need to be filed again, but new findings are always welcome.