請使用 GitHub 的私密漏洞回報提交未公開的安全或私隱問題。不要在公開 issue、pull request、截圖或測試資料中加入憑證、使用者圖片、真實應用資料、私人路徑或其他個人資料。
如問題涉及已洩露的 secret,請先撤銷或輪換該 secret,再提交只包含重現所需最少資料的私密報告。一般功能問題可使用公開 issue,但不得附上未公開漏洞細節。
目前只支援最新 GitHub Release 與 main。修正經過測試及發佈後,維護者會在不披露使用者或報告者資料的前提下提供必要的版本說明。
Use GitHub's private vulnerability reporting for undisclosed security or privacy issues. Do not place credentials, user images, production data, private paths, or other personal data in public issues, pull requests, screenshots, or fixtures.
If a secret has been exposed, revoke or rotate it first, then submit only the minimum information needed to reproduce the issue. Public issues remain appropriate for ordinary bugs that contain no sensitive or undisclosed security detail.
Only the latest GitHub Release and main are supported. Once a fix is tested and released, maintainers will publish the necessary version information without disclosing user or reporter data.