Replies: 6 comments 1 reply
|
The current channel is GitHub Discussions ? issues and PRs are closed upstream, and security reports are already being discussed there (#1923, #1863, #1789 are recent examples). Post with this template so maintainers can act fast:
Two gaps worth flagging upstream while you're at it:
I maintain the ecosystem bug radar (https://github.com/zoahdev/dsh-ecosystem) ? happy to track your finding there with a link back to your report. |
|
建议先不要在 Discussion、Issue、PR 或公开附件里提供漏洞细节、利用代码、真实路径、凭据或未脱敏会话记录。 我刚核对了仓库当前的公开配置:
因此目前不能可靠地指向一个“官方私密上报渠道”,也不应该猜测邮箱。比较安全的临时做法是:保留本帖作为不含细节的占位,只写受影响版本、平台和影响类别,并请维护者在这里提供私密联系方式。拿到官方渠道后,再私下发送最小复现、影响范围、环境、日志和建议修复方式。 同时建议维护者尽快启用 GitHub Private Vulnerability Reporting,并增加 |
|
如果这个反馈渠道说明对你有帮助,方便的话可以把我的回答标记为采纳(Mark as answer)。以后发现 DSH 安全问题的社区用户可以直接看到当前可用渠道和上报模板(环境/复现/影响/证据)。 If the channel guidance helped, accepting the answer would make it easier for future security reporters to find the recommended process. |
|
把"怎么系统地审计一个小插件"写成了完整方法论——七项清单 + 三个真实靶标的审计记录(全部干净,含文件+行号证据),以及"没发现也是资产"的原则: How to systematically audit a small plugin — https://zoahdev.github.io/blog/2026/08/17/how-to-audit-a-small-plugin.html 对想给 DSH 生态做安全贡献的人应该有用:选靶(处理不可信输入的小包)→ 先读风险文件 → 全仓搜高危 API → 验证防御而非只看关键词 → 只报站得住的发现。 |
|
整理了一个针对这 5 个 QVD 的社区补丁仓库(基于 0.1.2-alpha.2):52631/52632/52644/52646 四个有源码修复,57410 是版本核验;附逐项说明、Windows 一键验证脚本和 SHA-256。52632 的进程级读面残留也如实标注了,非官方发布,仅供参考。https://github.com/Delafroms/dsh-qvd-fixes |
|
新開發的軟體軟件多多少少都會有漏洞,其實我一直覺得官方能給SSL加密功能內部區網IP功能使用比較方便不是,雖然可能更不安全但這樣使用率就能提高,不可能一直在單台筆電前面,安全性是可增加改善的 |
Uh oh!
There was an error while loading. Please reload this page.
请问安全问题(漏洞)的反馈渠道是什么?
All reactions