Skip to content

Security: AS-AIGC/AS-FAQ-Bot

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

If you discover a security vulnerability within this project, please report it as soon as possible. We take all security reports seriously and will address them promptly.

Steps to Report a Vulnerability:

  1. Do not open a public issue. To protect the project and its users, we request that security vulnerabilities are reported via private communication.
  2. Email us at cclljj@gmail.com with the following information:
    • A description of the vulnerability and its potential impact.
    • Detailed steps to reproduce the vulnerability (proof of concept).
    • Any other relevant information that will help us to understand the issue.
  3. You will receive an acknowledgement within 48 hours. We will work with you to understand the issue and develop a fix.
  4. We will provide you with an estimated time frame for the fix. During this period, we may ask you for further information or feedback.

What We Do Next

Upon receiving your report, we will:

  1. Investigate the vulnerability to confirm its existence and impact.
  2. Work on a patch to fix the vulnerability.
  3. Notify the affected users and prepare a release with the fix.
  4. Credit you for the discovery if you wish, and if the vulnerability is confirmed and fixed.

Public Disclosure

We will not publicly disclose the details of the vulnerability until we have provided a patch and updated all affected versions. We believe this approach is the best way to protect our users.

Contact

For any questions or clarifications, you can contact us at cclljj@gmail.com.

Thank you for helping to keep our project secure!

There aren’t any published security advisories