diff --git a/SECURITY.md b/SECURITY.md index db8af99..a3d51b0 100644 --- a/SECURITY.md +++ b/SECURITY.md @@ -1,21 +1,38 @@ -# Security Policy +# Security Policy / 安全策略 / 安全政策 -## Supported Versions +> **简体中文 | 繁體中文 | English** — 请按需用任意一种语言阅读(Please read in any language as needed / 請依需求以任一語言閱讀)。 + +## Supported Versions / 支持的版本 / 支援的版本 The following versions of the project are currently being supported with security updates: +以下版本目前会收到安全更新: +以下版本目前會收到安全性更新: -| Version | Supported | +| Version / 版本 | Supported / 支持 / 支援 | | ------- | ------------------ | | 0.12.x | :white_check_mark: | | 0.11.x | :x: | | 0.10.x | :white_check_mark: | | < 0.10 | :x: | -## Reporting a Vulnerability +## Reporting a Vulnerability / 报告漏洞 / 回報漏洞 Please report security vulnerabilities by opening a private issue or contacting the maintainers directly. +请通过创建私有 issue 或直接联系维护者来报告安全漏洞。 +請透過建立私有 issue 或直接聯絡維護者來回報安全性漏洞。 -- **Where to report:** Open an issue on the repository or email the maintainers directly. Do not disclose vulnerabilities publicly before they have been addressed. -- **Response time:** You can expect an acknowledgement of your report within **48 hours**, and a status update on the reported vulnerability at least once per week. -- **What to expect if accepted:** The vulnerability will be assigned a severity level, tracked privately, and a fix will be prioritized based on severity. A security advisory and patch release will be published once the fix is ready. -- **What to expect if declined:** If the report is determined not to be a vulnerability, you will receive a detailed explanation of why it was declined. +- **Where to report / 在哪里报告 / 在哪裡回報:** Open an issue on the repository or email the maintainers directly. Do not disclose vulnerabilities publicly before they have been addressed. + 在仓库上创建 issue 或直接发送邮件给维护者。在漏洞被处理之前,请勿公开披露。 + 在儲存庫上建立 issue 或直接發送郵件給維護者。在漏洞被處理之前,請勿公開揭露。 + +- **Response time / 响应时间 / 回應時間:** You can expect an acknowledgement of your report within **48 hours**, and a status update on the reported vulnerability at least once per week. + 你将在 **48 小时** 内收到报告确认,并且每周至少收到一次漏洞处理进展更新。 + 您將在 **48 小時** 內收到回報確認,且每週至少收到一次漏洞處理進展更新。 + +- **What to expect if accepted / 若被接受 / 若被接受:** The vulnerability will be assigned a severity level, tracked privately, and a fix will be prioritized based on severity. A security advisory and patch release will be published once the fix is ready. + 漏洞将被评估严重程度并私下跟踪,修复优先级依据严重程度确定。修复就绪后会发布安全公告和补丁版本。 + 漏洞將被評估嚴重程度並私下追蹤,修復優先順序依嚴重程度決定。修復就緒後會發布安全性公告與修補程式版本。 + +- **What to expect if declined / 若被拒绝 / 若被拒絕:** If the report is determined not to be a vulnerability, you will receive a detailed explanation of why it was declined. + 如果报告被认定不是漏洞,你会收到详细说明,解释被拒绝的原因。 + 如果回報被認定並非漏洞,您會收到詳細說明,解釋被拒絕的原因。