如果你发现安全漏洞,请不要在 GitHub Issue 中公开报告。
If you discover a security vulnerability, please do not report it publicly via GitHub Issues.
- 发送邮件至 / Send email to: chinokoyuki@gmail.com
- 使用以下模板 / Use the following template:
Subject: [SECURITY] <简要描述 / brief description>
Description: <漏洞描述 / vulnerability description>
Steps to Reproduce: <复现步骤 / reproduction steps>
Impact: <影响范围 / impact assessment>
Suggested Fix: <修复建议 / suggested fix (optional)>
| 阶段 / Stage | 时间 / Timeframe |
|---|---|
| 确认收到 / Acknowledge receipt | 48 小时内 / Within 48 hours |
| 初步评估 / Initial assessment | 7 天内 / Within 7 days |
| 修复发布 / Fix release | 30 天内(严重漏洞优先)/ Within 30 days (critical prioritized) |
| 版本 / Version | 支持 / Supported |
|---|---|
| 0.2.x | ✅ |
| < 0.2 | ❌ |
- 始终从官方发布渠道获取二进制 / Always obtain binaries from official release channels
- 不要在公开 issue 中粘贴敏感信息 / Do not paste sensitive information in public issues
- 使用最新版本 / Use the latest version