If you discover a security vulnerability within this project, please report it as soon as possible. We take all security reports seriously and will address them promptly.
- Do not open a public issue. To protect the project and its users, we request that security vulnerabilities are reported via private communication.
- Email us at cclljj@gmail.com with the following information:
- A description of the vulnerability and its potential impact.
- Detailed steps to reproduce the vulnerability (proof of concept).
- Any other relevant information that will help us to understand the issue.
- You will receive an acknowledgement within 48 hours. We will work with you to understand the issue and develop a fix.
- We will provide you with an estimated time frame for the fix. During this period, we may ask you for further information or feedback.
Upon receiving your report, we will:
- Investigate the vulnerability to confirm its existence and impact.
- Work on a patch to fix the vulnerability.
- Notify the affected users and prepare a release with the fix.
- Credit you for the discovery if you wish, and if the vulnerability is confirmed and fixed.
We will not publicly disclose the details of the vulnerability until we have provided a patch and updated all affected versions. We believe this approach is the best way to protect our users.
For any questions or clarifications, you can contact us at cclljj@gmail.com.
Thank you for helping to keep our project secure!