Skip to content

Security: xsj57/xsj57.github.io

Security

SECURITY.md

Security Policy

πŸ›‘οΈ Supported Versions

We are committed to protecting user security. The following versions will receive security updates:

Version Support Status
1.0.x βœ… Supported
< 1.0 ❌ Not Supported

🚨 Reporting Security Issues

If you discover a security vulnerability, please do not report it publicly. Instead, please report it privately through the following methods:

GitHub Security Advisories

  1. Visit Security Advisories
  2. Click "Report a vulnerability"
  3. Fill in detailed security issue description

Please include [SECURITY] prefix in the email subject.

πŸ“‹ Report Requirements

To help us better understand and resolve issues, please include in your report:

  • Vulnerability Type: XSS, CSRF, information disclosure, etc.
  • Impact Scope: Which features are affected
  • Reproduction Steps: Detailed vulnerability reproduction steps
  • Expected Behavior: What should happen normally
  • Actual Behavior: What happens when the vulnerability is triggered
  • Environment Information: Browser version, operating system, etc.
  • Timestamp: Time when the vulnerability was discovered

⏱️ Response Time

We commit to respond within the following timeframes after receiving security reports:

  • Initial Confirmation: Within 24 hours
  • Detailed Assessment: Within 3 business days
  • Fix Plan: Within 7 business days
  • Fix Release: Determined by severity level

πŸ”’ Security Best Practices

To maintain project security, we recommend:

  • Regularly update dependencies
  • Use HTTPS protocol
  • Implement Content Security Policy (CSP)
  • Conduct regular security audits
  • Follow OWASP security guidelines

πŸ™ Acknowledgments

Thank you to all researchers and users who responsibly report security issues!


Note: Please do not discuss security issues in public Issues, as this may put other users at risk.

There aren’t any published security advisories