Skip to content

Security: chinokoyuki/HarmonyOS-Support

Security

SECURITY.md

安全策略 / Security Policy

报告漏洞 / Reporting a Vulnerability

如果你发现安全漏洞,请不要在 GitHub Issue 中公开报告

If you discover a security vulnerability, please do not report it publicly via GitHub Issues.

报告方式 / How to Report

  1. 发送邮件至 / Send email to: chinokoyuki@gmail.com
  2. 使用以下模板 / Use the following template:
Subject: [SECURITY] <简要描述 / brief description>

Description: <漏洞描述 / vulnerability description>
Steps to Reproduce: <复现步骤 / reproduction steps>
Impact: <影响范围 / impact assessment>
Suggested Fix: <修复建议 / suggested fix (optional)>

响应时间 / Response Time

阶段 / Stage 时间 / Timeframe
确认收到 / Acknowledge receipt 48 小时内 / Within 48 hours
初步评估 / Initial assessment 7 天内 / Within 7 days
修复发布 / Fix release 30 天内(严重漏洞优先)/ Within 30 days (critical prioritized)

支持的版本 / Supported Versions

版本 / Version 支持 / Supported
0.2.x
< 0.2

安全最佳实践 / Security Best Practices

  • 始终从官方发布渠道获取二进制 / Always obtain binaries from official release channels
  • 不要在公开 issue 中粘贴敏感信息 / Do not paste sensitive information in public issues
  • 使用最新版本 / Use the latest version

There aren't any published security advisories