ignorefile reads and writes ignore files. It runs no network code, spawns no
processes outside the test suite, and holds no credentials. The realistic
threat is a malformed or hostile .gitignore or configuration file causing a
panic, an infinite loop, or a rendered file that ignores something the author
did not intend to ignore -- the last of these being the most serious, because it
can silently commit a secret.
Report privately. Do not open a public issue.
Preferred: use GitHub's private reporting. Go to the Security tab, and under "Reporting" in the left sidebar choose Advisories, then "Report a vulnerability". Private vulnerability reporting is enabled on this repository.
If that is not available to you, email the maintainer: Elio Severo Junior elioseverojunior@gmail.com or elio@elio.eti.br.
When emailing, prefer a provider that does hop-to-hop (transport) encryption -- ideally one using MTA-STS, otherwise STARTTLS. That is weaker than end-to-end encryption, but it is enough here and it is something everyone can actually do.
Please include what the input was, what happened, and what you expected. A
.gitignore or config file that reproduces the problem is worth more than a
description of it.
You will get an acknowledgement within a week. Credit is given to reporters by default; say so if you would rather stay anonymous or pseudonymous, and that will be respected.
Patches are welcome. See docs/guidelines/CONTRIBUTION.md, and note that it forbids AI-generated pull requests.
Pre-alpha, nothing published to crates.io yet. Only main is supported; there
are no maintained release branches and no backports. This section will be
replaced once there is a released version.
Not promises -- these run in CI on every push, and you can read them in
.github/workflows/:
| Control | Where |
|---|---|
unsafe_code = "deny" workspace-wide; no escape hatch |
Cargo.toml |
unwrap/expect denied in production code (a panic is a DoS) |
.clippy.toml |
| Warnings are hard errors, including rustdoc | .cargo/config.toml |
RustSec advisory scan (cargo audit) |
hk audit step, run by the Lint job |
Licence, ban and source policy (cargo deny) |
hk deny step, run by the Lint job |
| Secret scanning (gitleaks) | hk gitleaks step, run by the Lint job |
Compiling at the declared MSRV, so rust-version cannot drift upward silently |
cicd.yml, MSRV job |
| Static analysis (CodeQL) | cicd.yml SAST job on every push; codeql.yml weekly |
| OpenSSF Scorecard | scorecards.yml |
| SLSA L3 provenance and Sigstore signing of release artifacts | publish.yml |
| A human reviewer required before anything reaches crates.io | crates-io deployment environment |
| Dependency updates and GitHub secret-scanning push protection | Dependabot, repo settings |
| 100% test coverage gate, including doctests | mise run coverage |
Correctness is a security property in this project. The differential test in
crates/ignorefile/tests/differential.rs checks agreement with git check-ignore on generated inputs, because a rendered file that disagrees with
git is exactly how a secret ends up committed.
In scope: a panic, hang, or excessive memory use on untrusted input; any case where importing then re-generating changes which files git ignores; a path traversal or unintended write outside the paths given on the command line.
Out of scope: the behaviour of git itself; a .gitignore that ignores the
wrong files because it was written that way; anything requiring an attacker who
already has write access to the repository or to your machine.