简体中文 | 繁體中文 | English — 请按需用任意一种语言阅读(Please read in any language as needed / 請依需求以任一語言閱讀)。
This project is self-hosted — there are no automatic OTA updates. "Supported" below means security fixes are released for these versions, which you apply by updating your own deployment (e.g. pull the new image / release and redeploy). 本项目为自部署项目,没有自动 OTA 更新。下表中的"支持"表示会为这些版本发布安全修复,需由你自行更新部署(例如拉取新镜像 / 新版本并重新部署)。 本專案為自部署專案,沒有自動 OTA 更新。下表中的「支援」表示會為這些版本發布安全性修復,需由您自行更新部署(例如拉取新映像檔 / 新版本並重新部署)。
| Version / 版本 | Supported / 支持 / 支援 |
|---|---|
| 0.12.x | ✅ |
| < 0.12 | ❌ |
Please report security vulnerabilities by opening a private issue or contacting the maintainers directly. 请通过创建私有 issue 或直接联系维护者来报告安全漏洞。 請透過建立私有 issue 或直接聯絡維護者來回報安全性漏洞。
-
Where to report / 在哪里报告 / 在哪裡回報: Open an issue on the repository or email the maintainers directly. Do not disclose vulnerabilities publicly before they have been addressed. 在仓库上创建 issue 或直接发送邮件给维护者。在漏洞被处理之前,请勿公开披露。 在儲存庫上建立 issue 或直接發送郵件給維護者。在漏洞被處理之前,請勿公開揭露。
-
Response time / 响应时间 / 回應時間: You can expect an acknowledgement of your report within 48 hours, and a status update on the reported vulnerability at least once per week. 你将在 48 小时 内收到报告确认,并且每周至少收到一次漏洞处理进展更新。 您將在 48 小時 內收到回報確認,且每週至少收到一次漏洞處理進展更新。
-
What to expect if accepted / 若被接受 / 若被接受: The vulnerability will be assigned a severity level, tracked privately, and a fix will be prioritized based on severity. A security advisory and patch release will be published once the fix is ready. 漏洞将被评估严重程度并私下跟踪,修复优先级依据严重程度确定。修复就绪后会发布安全公告和补丁版本。 漏洞將被評估嚴重程度並私下追蹤,修復優先順序依嚴重程度決定。修復就緒後會發布安全性公告與修補程式版本。
-
What to expect if declined / 若被拒绝 / 若被拒絕: If the report is determined not to be a vulnerability, you will receive a detailed explanation of why it was declined. 如果报告被认定不是漏洞,你会收到详细说明,解释被拒绝的原因。 如果回報被認定並非漏洞,您會收到詳細說明,解釋被拒絕的原因。