Files
minio/SECURITY.md
T
Feng Ruohang fd2ca1c6d2 docs: rebrand the repository documentation, templates and dashboards
README, README_ZH, SECURITY, COMPLIANCE, CONTRIBUTING, NOTICE,
code_of_conduct, the vulnerability and PR-etiquette documents, the GitHub issue
and pull request templates, and the docs/ tree all present Silo as the product.
The Grafana dashboards under docs/metrics/prometheus/grafana/ have their panel
titles and descriptions rebranded while every minio_* query, label and
expression is left alone, so existing alerts and recording rules keep matching.

The distinction the review demanded is applied per hit rather than by
search-and-replace:

- Product and command text becomes Silo and silo: install and run instructions,
  systemd examples, compose services, download links, badges.
- Protocol and interface text keeps MinIO: MINIO_* variables, minio_* metrics,
  x-minio-* headers, /minio/* routes, .minio.sys, arn:minio, and API field and
  error names.
- Attribution keeps MinIO and gains the fork's own: the AGPL obligations,
  original copyright, CREDITS and NOTICE stay, with the modification notice
  added alongside rather than replacing them.
- Historical and third-party references are left as facts, not rewritten for
  brand tidiness.

README and README_ZH each carry an explicit non-affiliation notice, document
the side-by-side package migration including the
/etc/systemd/system/silo.service.d/10-legacy-user.conf drop-in for keeping a
legacy UID/GID, and state that recursive chown is never performed. The trademark
attribution uses the policy's approved "based on MinIO technology" wording, not
the shortened form the policy rejects.

github.com/pgsty/minio links are left in place and labelled transitional. The
repository has not been renamed, and rewriting them now would produce documented
URLs that 404 until the cutover; they change in the cutover commit together with
the goreleaser release target, the OCI source label and the raw-content branch.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-06 08:49:30 +08:00

1.4 KiB

Security Policy

Silo is an independent, community-maintained object-storage server derived from the open-source MinIO server. The source repository retains the transitional name pgsty/minio until the coordinated repository cutover. Upstream MinIO security contacts do not handle Silo-specific fixes or release notes.

Supported Versions

Security fixes are tracked on the active development branch and summarized in docs/security/advisories.md. Only the current Silo release line is supported unless an advisory says otherwise.

Reporting a Vulnerability

For vulnerabilities in this fork:

  1. Follow the fork-specific expectations in VULNERABILITY_REPORT.md.
  2. Prefer this repository's private GitHub security advisory workflow.
  3. If private reporting is unavailable, contact the maintainers through the repository without publishing exploit details until a private channel is established.
  4. If you confirm the issue also affects upstream minio/minio, report it upstream separately.

Disclosure Process

Fork-specific fixes and user-visible upgrade notes are published in docs/security/advisories.md. The fork-specific triage and remediation process is described in VULNERABILITY_REPORT.md.