Skip to content

Security: UID9622/longhun-system

SECURITY.md

安全政策 / Security Policy

支持版本 / Supported Versions

以下版本当前接受安全更新 / The following versions currently receive security updates:

版本 / Version 支持状态 / Supported
最新版 / Latest
上一个次版本 / Previous minor
更早版本 / Older

报告漏洞 / Reporting a Vulnerability

请勿通过公开 Issue 报告安全漏洞。 Please do NOT report security vulnerabilities through public GitHub Issues.

中文报告方式

请通过以下方式私下报告安全漏洞:

  1. 邮件:发送至 longhun2025@petalmail.com
    • 标题格式:[SECURITY] longhun-system 安全漏洞报告
    • 可使用 GPG 加密(可选):A2D0092CEE2E5BA87035600924C3704A8CC26D5F
  2. GitHub Security Advisories:使用仓库的私密漏洞报告功能

报告应包含:

  • 漏洞类型(如 SQL 注入、XSS、任意代码执行)
  • 受影响版本
  • 详细复现步骤
  • 可能的影响范围
  • 修复建议(如有)

我们的承诺:

  • 24 小时内确认收到报告
  • 7 天内提供初步评估
  • 修复后通知报告者,并在 Release Notes 中致谢(须报告者同意)

English

Please report security vulnerabilities privately:

  1. Email: Send to longhun2025@petalmail.com
    • Subject: [SECURITY] longhun-system Vulnerability Report
    • Optional GPG encryption: A2D0092CEE2E5BA87035600924C3704A8CC26D5F
  2. GitHub Security Advisories: Use the private vulnerability reporting feature

Please include:

  • Vulnerability type (e.g., SQL injection, XSS, RCE)
  • Affected versions
  • Detailed reproduction steps
  • Potential impact scope
  • Suggested fix (if any)

Our commitment:

  • Acknowledge receipt within 24 hours
  • Provide initial assessment within 7 days
  • Credit reporters in Release Notes upon fix (with consent)

维护者 / Maintainer: @UID9622 GPG Key: A2D0092CEE2E5BA87035600924C3704A8CC26D5F

There aren't any published security advisories