ClipPort 目前处于 Beta 阶段,仅维护最新的 1.0.x-beta 代码和最新公开版本。
旧构建可能不会获得单独的安全修复。
请不要通过公开 Issue、Discussion 或 Pull Request 披露尚未修复的安全漏洞。
请打开仓库的 Security 页面,选择 Report a vulnerability,使用 GitHub 私密漏洞报告提交以下信息:
- 受影响版本或提交。
- 重现步骤和必要的测试文件说明。
- 实际影响及可被利用的条件。
- 已知的缓解方法或修复建议。
维护者会尽力在 7 天内确认报告,并在完成修复和发布安排前通过私密报告保持沟通。 请在双方协调公开时间之前保留漏洞细节。
如果 GitHub 私密报告入口暂时不可用,请通过维护者的 GitHub 主页 中公开的联系方式联系,不要创建包含漏洞细节的公开 Issue。
Only the latest 1.0.x-beta code and the latest public release are currently supported.
Do not disclose unpatched vulnerabilities in public issues, discussions, or pull requests.
Use the repository's Security → Report a vulnerability flow and include the affected version, reproduction steps, impact, exploit conditions, and any known mitigation.