Skip to content

Security: AstroAir/ai-quick-starter

Security

SECURITY.md

Security Policy / 安全策略

Supported Versions / 支持范围

This repository is currently maintained on a rolling basis.

当前仓库按滚动方式维护。

Version Supported Notes
main Yes Primary maintained branch
Latest tagged release Yes When tags are published
Older snapshots No Upgrade to the latest release or main

Reporting A Vulnerability / 漏洞报告方式

Please do not open a public issue for potential security vulnerabilities.

潜在安全漏洞请不要直接公开提 issue。

Instead, report privately through one of these channels:

请通过以下私密渠道报告:

What To Include / 请尽量提供

  • Affected file or skill path

  • Reproduction steps

  • Impact assessment

  • Proposed mitigation if available

  • 受影响的文件或技能路径

  • 复现步骤

  • 影响范围判断

  • 如果有的话,附上建议缓解方案

Response Expectations / 响应预期

  • Initial acknowledgement target: within 5 business days

  • Status updates: when triage meaningfully changes

  • Fix timing: depends on severity, maintainability, and available maintainer capacity

  • 初步确认目标:5 个工作日内

  • 状态更新:在分级结果发生明显变化时同步

  • 修复时机:取决于严重程度、可维护性和维护者时间

Security Notes / 额外说明

This repository may include skills that interact with third-party services, websites, or local tooling. Please avoid sharing tokens, personal data, or privileged environment details in public reports.

本仓库中的部分技能可能会调用第三方服务、网站或本地工具。公开报告时请避免附带令牌、个人数据或敏感环境信息。

There aren’t any published security advisories