Skip to content

Security: XiaojuCH/EnvCompass

SECURITY.md

Security Policy

EnvCompass 会读取本机开发工具信息和所选项目的有限 metadata。安全与隐私问题会被优先处理。

报告安全或隐私问题

  • 不要在公开 Issue 中粘贴 token、密码、私钥、完整私人路径或未经检查的完整诊断报告。
  • 如果仓库已启用 GitHub Private Vulnerability Reporting,请优先使用该入口。
  • 如果尚未启用,可以先创建一个不含敏感细节的 Issue,请维护者提供私下沟通方式。
  • 请说明受影响版本、影响、复现条件,以及已经确认可以安全公开的最小证据。

EnvCompass 的导出报告会过滤常见敏感模式,但不能保证识别所有未知凭据格式。分享前仍应快速检查。


Please do not put secrets, private keys, complete private paths, or an unreviewed full diagnosis report in a public issue. Prefer GitHub Private Vulnerability Reporting if it has been enabled; otherwise open a minimal public issue without sensitive details and ask the maintainers for a private channel.

There aren't any published security advisories