Security fixes are applied to the latest commit on the main branch. Older snapshots are not maintained as separate release lines unless a release note explicitly says otherwise.
Please do not open a public issue for authentication bypasses, credential exposure, remote code execution, private-data disclosure, or other exploitable behavior.
Use GitHub Private Vulnerability Reporting and include:
- the affected commit or version;
- the vulnerable route, plugin, or data flow;
- reproduction steps or a minimal proof of concept;
- expected and observed behavior;
- impact and deployment assumptions;
- any suggested remediation, if available.
Remove real QQ identifiers, access tokens, API keys, chat messages, and database contents from the report. If a minimal sample needs sensitive data, replace it with deterministic test values.
Maintainers will aim to acknowledge a complete report within seven days. Timelines for validation, remediation, and disclosure depend on severity and reproducibility. Please allow time for a fix and coordinated disclosure before publishing technical details.
AntiFraudBot is not a hosted service. Operators are responsible for HTTPS termination, network access control, strong administrator credentials, service-provider permissions, backups, log retention, and compliance with local privacy requirements.
安全修复默认应用于 main 分支最新提交。除非发布说明另有声明,旧快照不会作为独立维护分支持续获得安全更新。
请不要通过公开 Issue 披露鉴权绕过、凭据泄露、远程代码执行、隐私数据暴露或其他可利用问题。
请使用 GitHub 私密漏洞报告,并尽量提供:
- 受影响的提交或版本;
- 存在问题的接口、插件或数据流;
- 可复现步骤或最小化 PoC;
- 预期行为和实际行为;
- 影响范围及成立前提;
- 可选的修复建议。
提交前必须移除真实 QQ 号、Token、API Key、聊天内容和数据库数据。需要示例时,请使用确定性的测试值替代。
维护者将尽量在七日内确认内容完整的报告。验证、修复和披露时间取决于问题严重性和复现情况。请在修复和协调披露完成前避免公开技术细节。
AntiFraudBot 不是托管服务。部署者需要自行负责 HTTPS、网络访问控制、强管理员密码、第三方服务权限、备份、日志保留以及当地隐私合规要求。