Add SECURITY.md - #2
Merged
Merged
Conversation
Documents the private reporting channel, response targets and supported versions, and states the threat model explicitly: streams handed to Exploder are assumed attacker controlled, since this is the compression used inside MPQ and similar container formats. Records the one security-relevant limitation of the format. Maximum expansion measured against this implementation is roughly 137:1, stable across input sizes, so a 72,680 byte stream expands to 10,000,000 bytes. The byte[] returning overloads are unbounded; the callback overload with a caller-enforced cap aborts promptly, after reading only a fraction of the input rather than completing the work first. Both figures and the abort behaviour were measured, not estimated. Also notes that a flaw in the shared algorithm rather than this translation of it likely affects upstream PKLib and every other port, and should be flagged as such for coordinated disclosure. Closes the Scorecard Security-Policy finding. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes the OpenSSF Scorecard Security-Policy finding (medium), which scored 0 because no policy file was present.
What it covers
Exploderare assumed attacker controlled, since this is the compression used inside MPQ and similar containers. In scope: memory safety, non-termination, any exception other thanPkLibExceptionescaping, and incorrect output.The part worth reading
The format allows a decompression bomb, and that is a property of the format rather than a defect, so it is documented instead of "fixed".
Both figures in the policy were measured against this implementation, not estimated:
The
byte[]-returning overloads accumulate the whole result in memory with no size limit, so the policy says plainly not to use them on hostile input, and gives the callback pattern with a caller-enforced cap instead.I verified that mitigation actually behaves as advertised before documenting it. Throwing from the write callback aborts promptly: with a 1 MB cap against the bomb above, it stopped after 1,003,520 bytes written — within one 4096-byte block of the cap — having read only 8,192 of the 72,680 compressed bytes. It does not finish the work and fail at the end.
Also noted
Crc32is error detection, not a cryptographic hash, and the format has no integrity or authenticity guarantees. Called out explicitly so nobody mistakes it for tamper detection.Note on process
Opened as a PR rather than pushed straight to
main, so it goes through the review requirement just configured — and it gives the Scorecard Code-Review check its first approved changeset.No code changes; documentation only.