58 lines
1.9 KiB
Markdown
58 lines
1.9 KiB
Markdown
# Security Policy
|
|
|
|
## Supported Versions
|
|
|
|
We strongly recommend always using the latest version to benefit from the latest security updates.
|
|
|
|
## Reporting a Vulnerability
|
|
|
|
We take the security of our software very seriously. If you discover a security vulnerability, please follow these guidelines:
|
|
|
|
### How to Report
|
|
|
|
Please **DO NOT** create a public issue for security vulnerabilities.
|
|
|
|
Instead, report security vulnerabilities by emailing:
|
|
|
|
📧 **Email**: `modstart@163.com`
|
|
|
|
### What to Include
|
|
|
|
When reporting a security vulnerability, please include:
|
|
|
|
1. **Description**: A clear description of the vulnerability
|
|
2. **Steps to Reproduce**: Detailed steps to reproduce the issue
|
|
3. **Impact Assessment**: Your assessment of the potential impact
|
|
4. **Affected Versions**: Which versions are affected
|
|
5. **Proof of Concept**: If applicable, include a PoC or example exploit
|
|
6. **Suggested Fix**: If you have ideas on how to fix it (optional)
|
|
|
|
### Response Process
|
|
|
|
- **Initial Response**: We aim to respond within 48 hours
|
|
- **Status Updates**: We will keep you informed about the progress
|
|
- **Disclosure Coordination**: We will coordinate with you on the disclosure timeline
|
|
- **Credit**: We will credit you in the release notes (unless you prefer to remain anonymous)
|
|
|
|
### Responsible Disclosure
|
|
|
|
We ask that you:
|
|
|
|
- Give us reasonable time to fix the vulnerability before public disclosure
|
|
- Avoid exploiting the vulnerability beyond what is necessary to demonstrate it
|
|
- Do not access, modify, or delete data belonging to others
|
|
- Do not perform actions that could harm the availability of our services
|
|
|
|
## Security Updates
|
|
|
|
Security updates will be announced through:
|
|
|
|
- GitHub Releases
|
|
- Project Documentation
|
|
- Email notification to users who have reported issues
|
|
|
|
## Acknowledgments
|
|
|
|
We appreciate the security research community and welcome responsible disclosure of security vulnerabilities.
|
|
|