EnvCompass 会读取本机开发工具信息和所选项目的有限 metadata。安全与隐私问题会被优先处理。
- 不要在公开 Issue 中粘贴 token、密码、私钥、完整私人路径或未经检查的完整诊断报告。
- 如果仓库已启用 GitHub Private Vulnerability Reporting,请优先使用该入口。
- 如果尚未启用,可以先创建一个不含敏感细节的 Issue,请维护者提供私下沟通方式。
- 请说明受影响版本、影响、复现条件,以及已经确认可以安全公开的最小证据。
EnvCompass 的导出报告会过滤常见敏感模式,但不能保证识别所有未知凭据格式。分享前仍应快速检查。
Please do not put secrets, private keys, complete private paths, or an unreviewed full diagnosis report in a public issue. Prefer GitHub Private Vulnerability Reporting if it has been enabled; otherwise open a minimal public issue without sensitive details and ask the maintainers for a private channel.