Chinese | English
Never report vulnerabilities, credentials, private data, recovery details, or active abuse in a public issue, Discussion, meeting, or minutes.
Use GitHub private vulnerability reporting for the affected repository when available. Otherwise use the private contact published by that project or organization. If neither exists, privately contact a non-conflicted organization owner and provide only enough information to establish a secure route.
Include the affected project/version, impact, minimal reproduction information, whether exploitation appears active, and a safe contact method. Never send production secrets.
Each project remains responsible for its security response. The community may coordinate cross-project impact, but listing or discussion is not a security audit.
The target flow is: acknowledge; triage/contain; identify affected immutable versions; coordinate a fix; pause controlled distribution; notify observable users without exploit detail; document recovery/appeal; and publish a de-identified record when safe. Emergency action is reviewed within 72 hours. Profile rollback cannot undo external effects already caused by code.
Limit reports to responders who need access. Do not copy them into general boards or AI services without authorization and redaction. Review records for deletion after 90 days unless open or legally required. This policy promises no SLA, bounty, embargo acceptance, or security warranty.