From 498c9f54d348e9ddf1334ae28a59330bebda1a25 Mon Sep 17 00:00:00 2001 From: Peter Wang Date: Tue, 4 Aug 2026 20:52:22 +0800 Subject: [PATCH] add security according to policy --- README.md | 10 ++++------ README.zh_CN.md | 9 ++++----- SECURITY.md | 13 +++++++++++++ 3 files changed, 21 insertions(+), 11 deletions(-) create mode 100644 SECURITY.md diff --git a/README.md b/README.md index f42e7be..a6c51fa 100644 --- a/README.md +++ b/README.md @@ -14,7 +14,7 @@ English | [中文README](README.zh_CN.md) - [Installation, Compilation, and Execution](#installation-compilation-and-execution) - [Contribution](#contribution) - [Code of Conduct](#code-of-conduct) -- [Security](#security) +- [Security and privacy](#security-and-privacy) - [License](#license) ## Introduction @@ -96,12 +96,10 @@ Please check [Contributing](CONTRIBUTING.md) for more details. Please check [Code of Conduct](CODE_OF_CONDUCT.md) for more details. -## Security +## Security and privacy -If you discover a potential security issue in this project, or think you may -have discovered a security issue, we ask that you notify Bytedance Security via our [security center](https://security.bytedance.com/src) or [vulnerability reporting email](sec@bytedance.com). - -Please do **not** create a public GitHub issue. +This project takes security seriously. +For vulnerability reporting and supported versions, see [SECURITY.md](SECURITY.md) ## License diff --git a/README.zh_CN.md b/README.zh_CN.md index cc3cf3e..0e9a8cc 100644 --- a/README.zh_CN.md +++ b/README.zh_CN.md @@ -15,7 +15,7 @@ - [安装、编译、运行](#安装编译运行) - [贡献](#贡献) - [开源协议](#开源协议) -- [安全漏洞](#安全漏洞) +- [Security and privacy](#security-and-privacy) ## 项目介绍 @@ -107,10 +107,9 @@ Note: 本项目采用[Apache-2.0 License](LICENSE.txt)协议. -## 安全漏洞 +## Security and privacy -如果你在此项目中发现了一个潜在的安全问题,请联系[字节跳动安全中心](https://security.bytedance.com/src) 或发送邮件到[漏洞汇报](sec@bytedance.com). - -请**不要**创建公开的Github issue. +This project takes security seriously. +For vulnerability reporting and supported versions, see [SECURITY.md](SECURITY.md) diff --git a/SECURITY.md b/SECURITY.md new file mode 100644 index 0000000..8e7c923 --- /dev/null +++ b/SECURITY.md @@ -0,0 +1,13 @@ +## Security and privacy + +If you discover potential security issues in the project, or believe you may have found a security issue, please notify the ByteDance security team through our [security center](https://security.bytedance.com/src/) or [vulnerability reporting email](mailto:src@bytedance.com). Please do not create public GitHub Issues. + +We will assess the vulnerability based on the Common Vulnerability Scoring System (CVSS 3.1). The security team will keep you updated on key progress and may request further information or guidance from you. You are welcome to contact us via the email or website mentioned above to ask questions or discuss disclosure matters. + +To protect the security of our customers, ByteDance requests that you do not publish or share information regarding the vulnerability in any public forum, nor publish or share data involving users, until the vulnerability has been remediated and our users have been notified. Please understand that the time required for remediation depends on the severity of the vulnerability and the scope of the impact. + +Individuals, companies, and security teams may wish to publish security advisories on their own websites or other forums. Please contact us via the email or website mentioned above prior to publication to discuss the information that can be disclosed and to coordinate the disclosure timeline. + +## Bug Bounty Reward + +[For the policy of bug bounty reward](https://bytedance.larkoffice.com/docx/ZstQd7bbooDctqxBCAmcFasOngd), if you have any questions about the rules, please contact [https://src.bytedance.com/home](https://src.bytedance.com/home) for consultation.