Skip to content

Security: skygazer42/GustoBot

Security

SECURITY.md

Security Policy

Reporting a vulnerability

Please do not disclose suspected vulnerabilities in a public issue.

Use one of these private reporting channels:

  1. Open the repository's Security tab and select Report a vulnerability.
  2. If GitHub private vulnerability reporting is unavailable, email 207829897@qq.com with the subject [GustoBot Security].

Include the affected version or commit, reproduction steps, expected impact, and any suggested remediation. Please remove credentials, access tokens, personal data, and other unrelated secrets from the report.

We aim to acknowledge a report within 5 business days. We will investigate, coordinate a fix and disclosure timeline with the reporter, and publish an advisory when appropriate.

Supported versions

Security fixes are applied to the latest commit on the default develop branch. Older commits and forks are not maintained.


安全政策

报告安全漏洞

请勿在公开 Issue 中披露疑似漏洞的技术细节。

请使用以下任一私密渠道:

  1. 在仓库的 Security 页面选择 Report a vulnerability。
  2. 如果 GitHub 私密漏洞报告入口不可用,请发送邮件至 207829897@qq.com,主题注明 [GustoBot Security]。

报告中请包含受影响版本或提交、复现步骤、预期影响及可能的修复建议; 请移除凭据、访问令牌、个人信息以及与问题无关的敏感数据。

我们计划在 5 个工作日内确认收到报告,并与报告者协调修复及披露时间; 适当时会发布安全公告。

安全修复仅面向默认 develop 分支的最新提交,旧提交及派生仓库不在维护范围内。

There aren't any published security advisories