Skip to content

Security: ChenXu233/YaoXiang

Security

SECURITY.md

Security Policy

Supported Versions / 支持的版本

This project is currently in active development and has no stable release yet. All versions should be considered experimental and may contain security issues.

本项目目前处于积极开发阶段,尚无稳定版本。 所有版本均应视为实验性,可能存在安全问题。

Version Supported
0.x.x ⚠️ Best-effort

Reporting a Vulnerability / 漏洞报告

To report a security vulnerability, please send an email to:

Email: Woyerpa@outlook.com

请通过邮件报告安全漏洞:

邮箱: Woyerpa@outlook.com

What to expect / 预期处理流程

  1. We will acknowledge your report within 72 hours.

  2. We'll keep you updated on our progress.

  3. If the vulnerability is confirmed, we'll release a fix as soon as possible.

  4. 我们会在 72 小时内 确认收到报告

  5. 处理过程中会持续更新进度

  6. 确认漏洞后尽快发布修复

Scope / 范围

We consider security issues in:

  • Code execution vulnerabilities / 代码执行漏洞
  • Memory safety issues / 内存安全问题
  • Input validation flaws / 输入验证缺陷
  • Dependency vulnerabilities / 依赖项漏洞

Out of scope / 不包括

  • Social engineering attacks / 社会工程攻击
  • Physical security / 物理安全
  • Issues in third-party tools we use / 我们使用的第三方工具问题

There aren't any published security advisories