Please use GitHub private vulnerability reporting. Do not open a public issue for an unpatched vulnerability or include real credentials and customer data in a report.
请使用 GitHub 私密漏洞报告。未修复漏洞不要提交公开 issue,报告中也不要放入真实凭证或客户数据。
Include the affected version or commit, reproduction steps, impact, and a minimal proof of concept. We will acknowledge a valid report as soon as practical and coordinate disclosure after a fix is available.
请提供受影响版本或 commit、复现步骤、影响与最小化 PoC。确认有效后我们会尽快响应,并在修复可用后协商披露。
The official supported distribution is the source in this repository. Third-party binaries, forks, and deployments may have different security properties.
官方支持范围是本仓库源码。第三方安装包、fork 或部署可能具有不同的安全属性。
Use short-lived or fine-grained tokens with minimum permissions. Never commit tokens or copy them into issues, logs, screenshots, recordings, task prompts, or repositories used by agents. Rotate a credential immediately if exposure is suspected.
请使用短期或 fine-grained token,并只授予最小权限。不要把 token 放入 issue、日志、截图、录屏、任务提示或 Agent 使用的仓库;怀疑泄露时应立即轮换。