安全修复面向最新正式版本和 master。旧版本可能不会单独回补;修复通常随下一个补丁版本发布。
仓库公开并启用 GitHub Private vulnerability reporting 后,请从仓库的 Security → Report a vulnerability 私密提交。不要通过公开 Issue、Pull Request 或 Discussions 披露尚未修复的漏洞。
报告应包含受影响版本、影响范围、复现条件、最小验证步骤和建议缓解措施。请勿附带无权共享的 RAW、客户数据、凭据或其它机密信息。
项目会尽力确认和修复有效报告,但不承诺固定响应时限、漏洞奖励或对已停止支持版本进行回补。
Security fixes target the latest published release and master. Older versions may not receive separate backports.
After the repository is public and GitHub Private vulnerability reporting is enabled, use Security → Report a vulnerability. Do not disclose an unpatched vulnerability through a public Issue, Pull Request, or Discussion.
Include the affected version, impact, prerequisites, minimal reproduction, and possible mitigation. Do not attach RAW files, customer data, credentials, or confidential material that you are not authorized to share. Valid reports will be reviewed in good faith, but fixed response times, bug bounties, and backports are not guaranteed.