请求启用私密安全漏洞报告渠道 (Request to enable private vulnerability reporting)
Nobody has claimed this yet.
- Dominant language
- JavaScript
- Stars
- 11.1k
- Forks
- 2.2k
- PR merge metrics
- No merged PRs in 30d
Description
您好,感谢维护 Spug 这个项目。
我们在近期的安全审计中发现了若干可能影响 Spug 的安全问题,希望以非公开的方式负责任地向您披露完整细节。
目前该仓库尚未启用 GitHub 的「私密安全漏洞报告(Private Vulnerability Reporting)」功能,也未在 SECURITY.md 中提供其他私密联系方式,因此我们暂时没有安全的渠道提交细节。
能否请您启用私密漏洞报告,或提供一个安全的联系邮箱?启用方法见官方文档:
https://docs.github.com/en/code-security/security-advisories/working-with-repository-security-advisories/configuring-private-vulnerability-reporting-for-a-repository
一旦有可用的私密渠道,我们会立即提供完整的漏洞细节与复现步骤。为避免风险,本 issue 不包含任何漏洞的具体信息。
谢谢!
— zx (Jace),GitHub: @manus-use
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Open the repository's GitHub Security settings and review the linked private vulnerability reporting documentation first. The issue names SECURITY.md as the place for an alternative private contact. Done means enabling private vulnerability reporting or adding a secure contact method, then confirming that researchers can submit details privately.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- github
- Domain
- security
- Issue type
- Feature
- Difficulty
- 1/5
- Estimated time
- Under an hour
- Activity status
- Active
- Clarity
- Clearly specified
- Newbie friendliness
- 45/100