Skip to content

Commit 506d1d3

Browse files
EstrellaXDclaudehappy-otter
committed
docs: add SECURITY.md for vulnerability reporting
Add security policy with bilingual instructions (English/Chinese) for reporting vulnerabilities via GitHub Private Vulnerability Reporting or email contact. Closes #879 Generated with [Claude Code](https://claude.ai/code) via [Happy](https://happy.engineering) Co-Authored-By: Claude <noreply@anthropic.com> Co-Authored-By: Happy <yesreply@happy.engineering>
1 parent 5810d5e commit 506d1d3

1 file changed

Lines changed: 52 additions & 0 deletions

File tree

SECURITY.md

Lines changed: 52 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,52 @@
1+
# Security Policy / 安全政策
2+
3+
## Supported Versions / 支持的版本
4+
5+
| Version | Supported |
6+
| ------- | ------------------ |
7+
| 3.x | :white_check_mark: |
8+
| < 3.0 | :x: |
9+
10+
## Reporting a Vulnerability / 报告漏洞
11+
12+
### English
13+
14+
If you discover a security vulnerability in AutoBangumi, please report it responsibly:
15+
16+
1. **GitHub Private Vulnerability Reporting** (Recommended): Use [GitHub's private vulnerability reporting feature](https://github.com/EstrellaXD/Auto_Bangumi/security/advisories/new) to submit your report securely.
17+
18+
2. **Email**: Contact the maintainer directly at the email associated with the GitHub account [@EstrellaXD](https://github.com/EstrellaXD).
19+
20+
**Please do NOT:**
21+
- Open a public GitHub issue for security vulnerabilities
22+
- Disclose the vulnerability publicly before it has been addressed
23+
24+
**What to include in your report:**
25+
- Description of the vulnerability
26+
- Steps to reproduce the issue
27+
- Potential impact
28+
- Any suggested fixes (optional)
29+
30+
We will acknowledge receipt of your report within 48 hours and work to address the issue promptly.
31+
32+
---
33+
34+
### 中文
35+
36+
如果您在 AutoBangumi 中发现安全漏洞,请通过以下方式负责任地报告:
37+
38+
1. **GitHub 私密漏洞报告**(推荐):使用 [GitHub 的私密漏洞报告功能](https://github.com/EstrellaXD/Auto_Bangumi/security/advisories/new) 安全地提交您的报告。
39+
40+
2. **邮件**:直接联系维护者,使用 GitHub 账户 [@EstrellaXD](https://github.com/EstrellaXD) 关联的邮箱。
41+
42+
**请勿:**
43+
- 在公开的 GitHub Issue 中报告安全漏洞
44+
- 在漏洞被修复之前公开披露
45+
46+
**报告中请包含:**
47+
- 漏洞描述
48+
- 复现步骤
49+
- 潜在影响
50+
- 修复建议(可选)
51+
52+
我们将在 48 小时内确认收到您的报告,并尽快处理该问题。

0 commit comments

Comments
 (0)