Skip to content

Security: SlayTheCircle/.github

SECURITY.md

安全策略 / Security Policy

本页提供组织默认安全报告指引。项目自己的 SECURITY 与支持范围优先适用。

范围

接受组织维护的代码、构建与发布工具、发行包相关的安全报告。一般崩溃、玩法错误和安装咨询见获取帮助。游戏本体或第三方依赖的漏洞请报告对应上游;涉及本项目集成方式的问题可以在本项目私密报告中说明。

未另行约定时,优先处理最新正式发行与默认分支中的问题;尚未发行的项目以默认分支为准。历史版本的修复按实际影响评估,不承诺长期维护全部版本。

私密报告

进入受影响仓库的 Security → Advisories → Report a vulnerability。组织主页与公共配置的问题可使用 .github 的私密报告入口。

报告应包含受影响项目及版本、运行环境、复现步骤、影响范围和经过脱敏的证据。请勿在公开 Issue、讨论或工坊评论中发布未披露漏洞的利用细节、凭据或个人信息。

若某个仓库尚未提供私密报告按钮,可通过上述 .github 入口注明目标仓库;不要为了联系维护者而公开漏洞细节。

响应与披露

维护者按可用时间分诊、确认影响并协调修复,不承诺固定响应或修复期限,也不提供漏洞赏金。经确认的问题按适用情况通过安全公告或发行说明披露;公开利用细节前请与维护者协调。

English summary

Report vulnerabilities privately through the affected repository's Security → Advisories → Report a vulnerability. If that entry is unavailable, use SlayTheCircle/.github's private reporting channel and identify the affected project. Include versions, environment, reproduction steps, impact, and sanitized evidence. Project-specific policies take precedence. Response and fixes are best-effort; there is no bug bounty or guaranteed deadline.

There aren't any published security advisories