Skip to content

Security: ksukie/OpenFireAlert

SECURITY.md

Security Policy

简体中文

Supported Versions

Security fixes are considered for the current main branch. This repository does not maintain separate security-support branches.

Reporting a Vulnerability

Do not disclose suspected vulnerabilities in public issues, pull requests, discussions, screenshots, logs, or videos.

Use GitHub Private Vulnerability Reporting by opening the repository's private vulnerability report form. The report remains private to the reporter and repository maintainers until it is published.

Include, when possible:

  • the affected module and commit or version;
  • a clear impact description;
  • minimal reproduction steps or proof of concept;
  • relevant configuration context with all secrets, private addresses, and personal data removed;
  • a suggested mitigation, if you have one.

If the private report form is not available, do not publish technical details. Open a minimal public issue asking the maintainer to enable private vulnerability reporting, without describing the vulnerability itself.

Scope

Examples include exposed credentials, authentication or authorization flaws, unsafe control endpoints, data or video privacy exposure, dependency vulnerabilities, and weaknesses that could affect deployed devices or services.

Disclosure

Please allow the maintainer reasonable time to investigate and prepare a fix before publicly disclosing a vulnerability. Public disclosure should not include secrets, private deployment information, or proof that could endanger a live installation.

There aren't any published security advisories