PageSourceSearch

https://joplinapp.org/assets/js/354af097.dc8f4567.js

js joplinapp.org collected 2026-09-24 08:45:25 UTC 9,548 bytes, 1 lines download raw bytes

1"use strict";(self.webpackChunk_joplin_doc_builder=self.webpackChunk_joplin_doc_builder||[]).push([[4747],{3905:function(e,t,a){a.d(t,{Zo:function(){return c},kt:function(){return h}});var n=a(67294);function r(e,t,a){return t in e?Object.defineProperty(e,t,{value:a,enumerable:!0,configurable:!0,writable:!0}):e[t]=a,e}function i(e,t){var a=Object.keys(e);if(Object.getOwnPropertySymbols){var n=Object.getOwnPropertySymbols(e);t&&(n=n.filter((function(t){return Object.getOwnPropertyDescriptor(e,t).enumerable}))),a.push.apply(a,n)}return a}function o(e){for(var t=1;t<arguments.length;t++){var a=null!=arguments[t]?arguments[t]:{};t%2?i(Object(a),!0).forEach((function(t){r(e,t,a[t])})):Object.getOwnPropertyDescriptors?Object.defineProperties(e,Object.getOwnPropertyDescriptors(a)):i(Object(a)).forEach((function(t){Object.defineProperty(e,t,Object.getOwnPropertyDescriptor(a,t))}))}return e}function l(e,t){if(null==e)return{};var a,n,r=function(e,t){if(null==e)return{};var a,n,r={},i=Object.keys(e);for(n=0;n<i.length;n++)a=i[n],t.indexOf(a)>=0||(r[a]=e[a]);return r}(e,t);if(Object.getOwnPropertySymbols){var i=Object.getOwnPropertySymbols(e);for(n=0;n<i.length;n++)a=i[n],t.indexOf(a)>=0||Object.prototype.propertyIsEnumerable.call(e,a)&&(r[a]=e[a])}return r}var p=n.createContext({}),s=function(e){var t=n.useContext(p),a=t;return e&&(a="function"==typeof e?e(t):o(o({},t),e)),a},c=function(e){var t=s(e.components);return n.createElement(p.Provider,{value:t},e.children)},u="mdxType",d={inlineCode:"code",wrapper:function(e){var t=e.children;return n.createElement(n.Fragment,{},t)}},y=n.forwardRef((function(e,t){var a=e.components,r=e.mdxType,i=e.originalType,p=e.parentName,c=l(e,["components","mdxType","originalType","parentName"]),u=s(a),y=r,h=u["".concat(p,".").concat(y)]||u[y]||d[y]||i;return a?n.createElement(h,o(o({ref:t},c),{},{components:a})):n.createElement(h,o({ref:t},c))}));function h(e,t){var a=arguments,r=t&&t.mdxType;if("string"==typeof e||r){var i=a.length,o=new Array(i);o[0]=y;var l={};for(var p in t)hasOwnProperty.call(t,p)&&(l[p]=t[p]);l.originalType=e,l[u]="string"==typeof e?e:r,o[1]=l;for(var s=2;s<i;s++)o[s]=a[s];return n.createElement.apply(null,o)}return n.createElement.apply(null,a)}y.displayName="MDXCreateElement"},27778:function(e,t,a){a.r(t),a.d(t,{assets:function(){return p},contentTitle:function(){return o},default:function(){return d},frontMatter:function(){return i},metadata:function(){return l},toc:function(){return s}});var n=a(87462),r=(a(67294),a(3905));const i={sidebar_label:"Warrant Canary",title:"Warrant Canary",description:"This repository contains the official warrant canary for Joplin. The purpose of the warrant canary is to provide a regularly updated, cryptographically signed statement indicating that no secret le..."},o="Warrant Canary",l={unversionedId:"canary",id:"canary",title:"Warrant Canary",description:"This repository contains the official warrant canary for Joplin. The purpose of the warrant canary is to provide a regularly updated, cryptographically signed statement indicating that no secret le...",source:"@site/help/canary.md",sourceDirName:".",slug:"/canary",permalink:"/help/canary",draft:!1,editUrl:"https://github.com/laurent22/joplin/tree/dev/readme/canary.md",tags:[],version:"current",frontMatter:{sidebar_label:"Warrant Canary",title:"Warrant Canary",description:"This repository contains the official warrant canary for Joplin. The purpose of the warrant canary is to provide a regularly updated, cryptographically signed statement indicating that no secret le..."},sidebar:"helpSidebar",previous:{title:"Joplin statistics",permalink:"/help/about/stats"},next:{title:"CLA Consent Records",permalink:"/help/cla/"}},p={},s=[{value:"Location of the Canary",id:"location-of-the-canary",level:2},{value:"Canary Signing Key",id:"canary-signing-key",level:2},{value:"Updating the canary file",id:"updating-the-canary-file",level:2},{value:"Key Rotation Policy",id:"key-rotation-policy",level:2},{value:"Key Rotation Procedure",id:"key-rotation-procedure",level:2},{value:"1. Generate a New Key",id:"1-generate-a-new-key",level:3}
1,{value:"2. Publish the New Key",id:"2-publish-the-new-key",level:3},{value:"3. Update Documentation",id:"3-update-documentation",level:3},{value:"Update the README",id:"update-the-readme",level:4},{value:"Update updateCanary.ts",id:"update-updatecanaryts",level:4},{value:"4. Transitional Signing",id:"4-transitional-signing",level:3}],c={toc:s},u="wrapper";function d(e){let{components:t,...a}=e;return(0,r.kt)(u,(0,n.Z)({},c,a,{components:t,mdxType:"MDXLayout"}),(0,r.kt)("h1",{id:"warrant-canary"},"Warrant Canary"),(0,r.kt)("div",{className:"donate-links"},(0,r.kt)("p",null,(0,r.kt)("a",{parentName:"p",href:"https://www.paypal.com/donate/?hosted_button_id=WQCERTSSLCC7U"},(0,r.kt)("img",{parentName:"a",src:"https://raw.githubusercontent.com/laurent22/joplin/dev/Assets/WebsiteAssets/images/badges/Donate-PayPal-green.svg",alt:"Donate using PayPal"}))," ",(0,r.kt)("a",{parentName:"p",href:"https://github.com/sponsors/laurent22/"},(0,r.kt)("img",{parentName:"a",src:"https://raw.githubusercontent.com/laurent22/joplin/dev/Assets/WebsiteAssets/images/badges/GitHub-Badge.svg",alt:"Sponsor on GitHub"}))," ",(0,r.kt)("a",{parentName:"p",href:"https://www.patreon.com/joplin"},(0,r.kt)("img",{parentName:"a",src:"https://raw.githubusercontent.com/laurent22/joplin/dev/Assets/WebsiteAssets/images/badges/Patreon-Badge.svg",alt:"Become a patron"}))," ",(0,r.kt)("a",{parentName:"p",href:"https://joplinapp.org/donate/#donations"},(0,r.kt)("img",{parentName:"a",src:"https://raw.githubusercontent.com/laurent22/joplin/dev/Assets/WebsiteAssets/images/badges/Donate-IBAN.svg",alt:"Donate using IBAN"})))),(0,r.kt)("p",null,"This repository contains the official warrant canary for Joplin."),(0,r.kt)("p",null,"The purpose of the warrant canary is to provide a regularly updated, cryptographically signed statement indicating that no secret legal orders, gag orders, or similar directives have been received as of the stated date."),(0,r.kt)("p",null,"If such an order were ever received and disclosure were legally prohibited, the canary would cease to be updated."),(0,r.kt)("h2",{id:"location-of-the-canary"},"Location of the Canary"),(0,r.kt)("p",null,"The current signed canary is published at:"),(0,r.kt)("p",null,(0,r.kt)("a",{parentName:"p",href:"https://github.com/laurent22/joplin/raw/dev/readme/canary.txt"},"https://github.com/laurent22/joplin/raw/dev/readme/canary.txt")),(0,r.kt)("h2",{id:"canary-signing-key"},"Canary Signing Key"),(0,r.kt)("p",null,"The canary is signed using a dedicated OpenPGP key. It is linked from the canary.txt file."),(0,r.kt)("p",null,"Its fingerprint is present in the canary.txt file itself and duplicated at:"),(0,r.kt)("p",null,(0,r.kt)("a",{parentName:"p",href:"https://github.com/laurent22/joplin/blob/dev/README.md"},"https://github.com/laurent22/joplin/blob/dev/README.md")),(0,r.kt)("h2",{id:"updating-the-canary-file"},"Updating the canary file"),(0,r.kt)("p",null,"Run ",(0,r.kt)("inlineCode",{parentName:"p"},"yarn updateCanary")," from the root of the repository and follow the prompt."),(0,r.kt)("h2",{id:"key-rotation-policy"},"Key Rotation Policy"),(0,r.kt)("p",null,"The canary signing key may be rotated for the following reasons:"),(0,r.kt)("ul",null,(0,r.kt)("li",{parentName:"ul"},"Key expiry"),(0,r.kt)("li",{parentName:"ul"},"Suspected compromise"),(0,r.kt)("li",{parentName:"ul"},"Maintainer transition"),(0,r.kt)("li",{parentName:"ul"},"Operational upgrades (e.g. hardware-backed signing)")),(0,r.kt)("p",null,"Key rotation will never be performed silently."),(0,r.kt)("h2",{id:"key-rotation-procedure"},"Key Rotation Procedure"),(0,r.kt)("h3",{id:"1-generate-a-new-key"},"1. Generate a New Key"),(0,r.kt)("p",null,"Create a new dedicated OpenPGP signing key."),(0,r.kt)("p",null,"Export the new public key in ASCII-armoured format."),(0,r.kt)("h3",{id:"2-publish-the-new-key"},"2. Publish the New Key"),(0,r.kt)("p",null,"Add the new public key to:"),(0,r.kt)("p",null,(0,r.kt)("a",{parentName:"p",href:"https://github.com/laurent22/joplin/raw/dev/Assets/keys/joplin-canary-signing-key.asc"},"https://github.com/laurent22/joplin/raw/dev/Assets/keys/joplin-canary-signing-key.asc")),(0,r.kt)("h3",{id:"3-update-documentation"},"3. Update Documentation"),(0,r.kt)("h4",{id:"update-the-readme"},"Update the README"),(0,r.kt)("ul",null,(0,r.kt)("li",{parentName:"ul"},"Mark the new fingerprint as ",(0,r.kt)("strong",{parentName:"li"},"Active")),(0,r.kt)("li",{parentName:"ul"},"Mark the previous fingerprint as ",(0,r.kt)("strong",{parentName:"li"},"Retired")),(0,r.kt)("li",{parentName:"ul"},"Document the rotation date")),(0,r.kt)("p",null,"Example:"),(0,r.kt)("pre",null,(0,r.kt)("code",{parentName:"pre"},"Active Canary Signing Key:\nNEW FINGERPRINT\n\nPrevious Key (retired 2028-02-18):\nOLD FINGERPRINT\n")),(0,r.kt)("h4",{id:"update-updatecanaryts"},"Update updateCanary.ts"),(0,r.kt)("p",null,"Add the new fingerprint to the canary template."),(0,r.kt)("h3",{id:"4-transitional-signing"}
1,"4. Transitional Signing"),(0,r.kt)("p",null,"For the first canary issued after rotation:"),(0,r.kt)("ul",null,(0,r.kt)("li",{parentName:"ul"},"Sign with the new key"),(0,r.kt)("li",{parentName:"ul"},"Optionally also sign with the old key")),(0,r.kt)("p",null,"This creates a cryptographic bridge between the two identities."),(0,r.kt)("p",null,"If the old key is compromised, do not dual-sign. Instead, publish a revocation statement."))}d.isMDXComponent=!0}}]);

Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.