Security fixes are applied to the main branch and, when appropriate, to the latest published release. Older snapshots are retained for reproducibility and may not receive backported fixes.
安全修复适用于 main 分支,并在适当情况下更新至最新正式发布版本。旧快照为保证可复现性而保留,不承诺回溯修复。
Please report suspected vulnerabilities or accidental disclosure of credentials privately by email:
请勿在公开 Issue、Discussion、Pull Request 或日志中粘贴密钥、令牌、个人数据、未公开利用方法或其他敏感信息。
Include, where possible:
- the affected file, commit, tag, or release;
- reproducible steps and the expected impact;
- the operating environment and relevant dependency versions;
- a minimal proof of concept or suggested mitigation that contains no live credentials.
如条件允许,请提供受影响的文件、提交或版本,可复现步骤、潜在影响、运行环境与依赖版本,以及不含真实凭据的最小复现或修复建议。
We aim to acknowledge a complete report within five business days. Validation and remediation timelines depend on severity and reproducibility. Please allow a reasonable remediation period before public disclosure.
完整报告通常会在五个工作日内得到确认。验证与修复时间取决于严重程度和可复现性;在公开披露前,请预留合理的修复时间。
This channel is for software vulnerabilities, supply-chain risks, exposed secrets, unsafe workflows, and security defects in the published repository. Scientific disagreements, requests for additional calculations, and interpretation questions should use the repository's scientific review templates instead.
本渠道仅用于软件漏洞、供应链风险、秘密泄漏、不安全工作流及公开仓库中的安全缺陷。科学观点分歧、补充计算请求和结果解释问题,请使用项目的科学审查模板。
The project is provided under the Apache-2.0 license and its stated warranty limitations. This policy defines the reporting process; it does not extend the license warranty.
本项目遵循 Apache-2.0 许可证及其免责声明。本政策仅规定安全报告流程,不扩展许可证所载保证。