Track bundled vendor runtime sources
This commit is contained in:
57
vendor/aigcpanel/SECURITY.md
vendored
Normal file
57
vendor/aigcpanel/SECURITY.md
vendored
Normal file
@@ -0,0 +1,57 @@
|
||||
# Security Policy
|
||||
|
||||
## Supported Versions
|
||||
|
||||
We strongly recommend always using the latest version to benefit from the latest security updates.
|
||||
|
||||
## Reporting a Vulnerability
|
||||
|
||||
We take the security of our software very seriously. If you discover a security vulnerability, please follow these guidelines:
|
||||
|
||||
### How to Report
|
||||
|
||||
Please **DO NOT** create a public issue for security vulnerabilities.
|
||||
|
||||
Instead, report security vulnerabilities by emailing:
|
||||
|
||||
📧 **Email**: `modstart@163.com`
|
||||
|
||||
### What to Include
|
||||
|
||||
When reporting a security vulnerability, please include:
|
||||
|
||||
1. **Description**: A clear description of the vulnerability
|
||||
2. **Steps to Reproduce**: Detailed steps to reproduce the issue
|
||||
3. **Impact Assessment**: Your assessment of the potential impact
|
||||
4. **Affected Versions**: Which versions are affected
|
||||
5. **Proof of Concept**: If applicable, include a PoC or example exploit
|
||||
6. **Suggested Fix**: If you have ideas on how to fix it (optional)
|
||||
|
||||
### Response Process
|
||||
|
||||
- **Initial Response**: We aim to respond within 48 hours
|
||||
- **Status Updates**: We will keep you informed about the progress
|
||||
- **Disclosure Coordination**: We will coordinate with you on the disclosure timeline
|
||||
- **Credit**: We will credit you in the release notes (unless you prefer to remain anonymous)
|
||||
|
||||
### Responsible Disclosure
|
||||
|
||||
We ask that you:
|
||||
|
||||
- Give us reasonable time to fix the vulnerability before public disclosure
|
||||
- Avoid exploiting the vulnerability beyond what is necessary to demonstrate it
|
||||
- Do not access, modify, or delete data belonging to others
|
||||
- Do not perform actions that could harm the availability of our services
|
||||
|
||||
## Security Updates
|
||||
|
||||
Security updates will be announced through:
|
||||
|
||||
- GitHub Releases
|
||||
- Project Documentation
|
||||
- Email notification to users who have reported issues
|
||||
|
||||
## Acknowledgments
|
||||
|
||||
We appreciate the security research community and welcome responsible disclosure of security vulnerabilities.
|
||||
|
||||
Reference in New Issue
Block a user