openspug / openspug/spug

请求启用私密安全漏洞报告渠道 (Request to enable private vulnerability reporting)

Open
#759 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
JavaScript
Stars
11.1k
Forks
2.2k
PR merge metrics
No merged PRs in 30d

Description

您好,感谢维护 Spug 这个项目。

我们在近期的安全审计中发现了若干可能影响 Spug 的安全问题,希望以非公开的方式负责任地向您披露完整细节。

目前该仓库尚未启用 GitHub 的「私密安全漏洞报告(Private Vulnerability Reporting)」功能,也未在 SECURITY.md 中提供其他私密联系方式,因此我们暂时没有安全的渠道提交细节。

能否请您启用私密漏洞报告,或提供一个安全的联系邮箱?启用方法见官方文档:
https://docs.github.com/en/code-security/security-advisories/working-with-repository-security-advisories/configuring-private-vulnerability-reporting-for-a-repository

一旦有可用的私密渠道,我们会立即提供完整的漏洞细节与复现步骤。为避免风险,本 issue 不包含任何漏洞的具体信息。

谢谢!

— zx (Jace),GitHub: @manus-use

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Open the repository's GitHub Security settings and review the linked private vulnerability reporting documentation first. The issue names SECURITY.md as the place for an alternative private contact. Done means enabling private vulnerability reporting or adding a secure contact method, then confirming that researchers can submit details privately.

Written by the indexing model from the issue text.

Assessment

Tech stack
github
Domain
security
Issue type
Feature
Difficulty
1/5
Estimated time
Under an hour
Activity status
Active
Clarity
Clearly specified
Newbie friendliness
45/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.