Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
19 changes: 19 additions & 0 deletions .github/PULL_REQUEST_TEMPLATE.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,19 @@
## Summary
<!-- What does this PR change, and why? -->

## Testing
<!-- This is cryptographic software - a change that looks correct in the diff can still silently
break encryption/decryption. Delete lines that don't apply to this PR. -->
- [ ] Build succeeds (`go build .` from `src/`, not naming `ZeeCrypt.go` directly)
- [ ] Encrypt → decrypt round-trip: normal mode
- [ ] Encrypt → decrypt round-trip: paranoid mode
- [ ] Encrypt → decrypt round-trip: keyfiles (ordered and unordered)
- [ ] Encrypt → decrypt round-trip: deniability
- [ ] Encrypt → decrypt round-trip: Reed-Solomon
- [ ] Encrypt → decrypt round-trip: split/recombine
- [ ] Wrong password on decrypt still fails as expected
- [ ] Not applicable (docs/CI/packaging-only change)

## Breaking changes
<!-- Does this change the on-disk volume format, or anything else that breaks compatibility
with volumes from earlier versions? If so, call it out explicitly here. -->
70 changes: 70 additions & 0 deletions CODE_OF_CONDUCT.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,70 @@
# Contributor Covenant Code of Conduct

## Our Pledge

We as members, contributors, and leaders pledge to make participation in our
community a harassment-free experience for everyone, regardless of age, body
size, visible or invisible disability, ethnicity, sex characteristics, gender
identity and expression, level of experience, education, socio-economic status,
nationality, personal appearance, race, religion, or sexual identity
and orientation.

We pledge to act and interact in ways that contribute to an open, welcoming,
diverse, inclusive, and healthy community.

## Our Standards

Examples of behavior that contributes to a positive environment for our
community include:

* Demonstrating empathy and kindness toward other people
* Being respectful of differing opinions, viewpoints, and experiences
* Giving and gracefully accepting constructive feedback
* Accepting responsibility and apologizing to those affected by our mistakes,
and learning from the experience
* Focusing on what is best not just for us as individuals, but for the
overall community

Examples of unacceptable behavior include:

* The use of sexualized language or imagery, and sexual attention or advances
of any kind
* Trolling, insulting or derogatory comments, and personal or political attacks
* Public or private harassment
* Publishing others' private information, such as a physical or email
address, without their explicit permission
* Other conduct which could reasonably be considered inappropriate in a
professional setting

## Enforcement Responsibilities

Project maintainers are responsible for clarifying and enforcing our standards
of acceptable behavior and will take appropriate and fair corrective action in
response to any behavior that they deem inappropriate, threatening, offensive,
or harmful.

## Scope

This Code of Conduct applies within all community spaces (issues, pull
requests, discussions) and also applies when an individual is officially
representing the community in public spaces.

## Enforcement

Instances of abusive, harassing, or otherwise unacceptable behavior may be
reported to the maintainer, [@TheZeekA](https://github.com/TheZeekA), by
contacting them directly on GitHub or via a private security advisory on this
repository. All complaints will be reviewed and investigated promptly and
fairly.

All maintainers are obligated to respect the privacy and security of the
reporter of any incident.

## Attribution

This Code of Conduct is adapted from the [Contributor Covenant][homepage],
version 2.1, available at
[https://www.contributor-covenant.org/version/2/1/code_of_conduct.html][v2.1].

[homepage]: https://www.contributor-covenant.org
[v2.1]: https://www.contributor-covenant.org/version/2/1/code_of_conduct.html
41 changes: 41 additions & 0 deletions CONTRIBUTING.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,41 @@
# Contributing to ZeeCrypt

Thanks for wanting to contribute! ZeeCrypt is actively maintained and open to bug reports, feature requests, and pull requests.

## Before you start

- For anything beyond a small fix, consider opening an issue first to discuss the change — this avoids wasted work if the approach needs adjusting.
- For security vulnerabilities, see [SECURITY.md](SECURITY.md) instead of opening a public issue or PR.
- Read the [Code of Conduct](CODE_OF_CONDUCT.md).

## Building from source

See [src/README.md](src/README.md) for full build instructions. In short:
```
cd src
go build -ldflags="-s -w -H=windowsgui -extldflags=-static" .
```
Note the `.` at the end rather than naming `ZeeCrypt.go` directly — Go only auto-links the `.syso` icon resource files when building the package as a whole.

## Making changes

This repo uses two long-lived branches:
- **`testing`** — active development. Push feature branches and open PRs against this.
- **`main`** — release branch. Protected: changes only land here via PR from `testing` (or a fix branch), typically once a batch of work on `testing` is ready to ship.

Workflow for a change:
1. Branch off `testing`
2. Make your change, and if you touch the encryption/decryption code, actually build and round-trip test it (encrypt then decrypt) — normal mode, paranoid mode, keyfiles, deniability, Reed-Solomon, and split/recombine as relevant to your change. This is cryptographic software; a change that looks correct but silently breaks decryption is worse than no change at all.
3. Open a PR into `testing`
4. Once merged, a maintainer will fold `testing` into `main` via a separate PR when it's ready for release

## Reporting bugs

Please include:
- ZeeCrypt version (shown in the window title)
- Steps to reproduce
- What you expected vs. what happened

## Style

This is a single-file Go application (`src/ZeeCrypt.go`). Match the existing style — run `gofmt` before committing. There's no test suite; changes to the cryptographic code path need to be manually verified by actually building and round-tripping real files (see above), since it can't be validated by reading the diff alone.
2 changes: 1 addition & 1 deletion README.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@

ZeeCrypt is a very small, very simple, yet very secure encryption tool that you can use to protect your files. It's a Windows-only fork of [Picocrypt](https://github.com/Picocrypt/Picocrypt), designed to be the <i>go-to</i> tool for file encryption, with a focus on security, simplicity, and reliability. ZeeCrypt uses the secure XChaCha20 cipher and the Argon2id key derivation function to provide a high level of security.

🚀 **This repo is actively maintained.** Unlike the original (now-archived) Picocrypt, ZeeCrypt is under active development — bug reports, feature requests, and suggestions are welcome, so feel free to open an issue.
🚀 **This repo is actively maintained.** Unlike the original (now-archived) Picocrypt, ZeeCrypt is under active development — bug reports, feature requests, and suggestions are welcome, so feel free to open an issue. See [CONTRIBUTING.md](CONTRIBUTING.md) if you'd like to contribute code, and [SECURITY.md](SECURITY.md) to report a vulnerability.

<br>
<p align="center"><img align="center" src="/images/screenshot.png" width="318" alt="ZeeCrypt"></p>
Expand Down
29 changes: 29 additions & 0 deletions SECURITY.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,29 @@
# Security Policy

## Supported Versions

Only the latest released version of ZeeCrypt is supported with security fixes. Older versions, and volumes encrypted with them, may not be compatible with the latest release — see [Changelog.md](Changelog.md) for breaking changes between versions.

## Reporting a Vulnerability

**Please do not open a public GitHub issue for security vulnerabilities.**

Instead, use GitHub's private vulnerability reporting for this repository:

1. Go to the [Security tab](https://github.com/TheZeekA/ZeeCrypt/security)
2. Click **Report a vulnerability**

This opens a private conversation with the maintainer that isn't visible to the public until it's resolved.

If you'd rather not use GitHub's reporting tool, you can contact [@TheZeekA](https://github.com/TheZeekA) directly.

Please include:
- A description of the vulnerability and its potential impact
- Steps to reproduce it, or a proof of concept if possible
- The version of ZeeCrypt affected

You should expect an initial response within a few days. There's no bug bounty program, but you'll be credited (if you'd like) once a fix is released.

## Scope

ZeeCrypt is designed for the offline security of encrypted volumes and assumes the host machine it runs on is trusted — see the [Security section of the README](README.md#security) and [Internals.md](Internals.md) for the threat model and known limitations (including PCC-004, an already-documented low-severity issue). Reports about that specific documented limitation don't need to be filed again, but new findings are always welcome.