mirror of
https://github.com/jeecgboot/JeecgBoot.git
synced 2026-08-26 14:48:55 +00:00
漏洞反馈
This commit is contained in:
parent
13003d6201
commit
91cb483126
50
jeecg-boot/.github/SECURITY.md
vendored
Normal file
50
jeecg-boot/.github/SECURITY.md
vendored
Normal file
@ -0,0 +1,50 @@
|
||||
# Security Policy / 安全策略
|
||||
|
||||
## Supported Versions / 支持版本
|
||||
|
||||
Security fixes are generally provided for the latest released version of JeecgBoot. Please upgrade to the latest release before reporting an issue that may already have been fixed.
|
||||
|
||||
JeecgBoot 原则上仅为最新正式版本提供安全修复。报告可能已经修复的问题前,请先升级到最新版本进行确认。
|
||||
|
||||
| Version / 版本 | Supported / 是否支持 |
|
||||
| --- | --- |
|
||||
| Latest release / 最新正式版 | Yes / 是 |
|
||||
| Older releases / 历史版本 | No / 否 |
|
||||
|
||||
## Reporting a Vulnerability / 报告安全漏洞
|
||||
|
||||
Please report suspected security vulnerabilities through [GitHub Private Vulnerability Reporting](https://github.com/jeecgboot/JeecgBoot/security/advisories/new).
|
||||
|
||||
如发现疑似安全漏洞,请通过 [GitHub 私密漏洞报告](https://github.com/jeecgboot/JeecgBoot/security/advisories/new) 提交。
|
||||
|
||||
**Do not disclose vulnerability details in a public GitHub issue, discussion, pull request, or other public channel before a fix is available.**
|
||||
|
||||
**在修复发布前,请勿在公开的 GitHub Issue、Discussion、Pull Request 或其他公开渠道披露漏洞细节。**
|
||||
|
||||
Please include as much of the following information as possible:
|
||||
|
||||
- Affected JeecgBoot version, branch, and deployment mode
|
||||
- Vulnerability type and affected component or endpoint
|
||||
- Required permissions and prerequisites
|
||||
- Reproduction steps or a minimal proof of concept
|
||||
- Security impact and possible attack scenarios
|
||||
- Suggested remediation, if available
|
||||
|
||||
请尽可能提供以下信息:
|
||||
|
||||
- 受影响的 JeecgBoot 版本、分支和部署模式
|
||||
- 漏洞类型以及受影响的组件或接口
|
||||
- 利用所需权限和前置条件
|
||||
- 复现步骤或最小化验证代码(PoC)
|
||||
- 安全影响和可能的攻击场景
|
||||
- 修复建议(如有)
|
||||
|
||||
## Disclosure Process / 披露流程
|
||||
|
||||
Maintainers will review the report privately and may request additional information. If the report is confirmed, we will coordinate remediation and public disclosure with the reporter. Please allow a reasonable amount of time for investigation and remediation before any public disclosure.
|
||||
|
||||
维护者将对报告进行私密审查,并可能要求补充信息。如果漏洞得到确认,我们会与报告者协调修复及公开披露。请在公开漏洞信息前,为调查和修复预留合理时间。
|
||||
|
||||
Thank you for helping keep JeecgBoot and its users secure.
|
||||
|
||||
感谢你帮助 JeecgBoot 及其用户提升安全性。
|
||||
Loading…
x
Reference in New Issue
Block a user