Skip to content

Security: woooooooooolf/deskpet3d

SECURITY.md

Security Policy

中文 | English

中文说明

支持范围

安全修复以最新发布版本和 main 分支为主要支持范围。已被新版本替代的旧版本可能不会单独修复。

报告安全漏洞

请不要通过公开 Issue、Discussion 或 PR 披露尚未修复的漏洞细节。仓库公开并启用 Private vulnerability reporting 后,请使用仓库 Security → Report a vulnerability 页面提交私密报告:

https://github.com/woooooooooolf/deskpet3d/security/advisories/new

如果该入口暂时不可用,可以创建一个不包含漏洞细节的最小 Issue,请求维护者建立私密沟通方式。不要在其中附加利用代码、Token、私人模型或敏感日志。

报告应尽可能包含受影响版本、Windows 环境、风险影响、稳定复现步骤和建议缓解方式。项目主要依赖 AI 完成分析和迭代,报告内容可能由 AI 工具辅助处理,因此请只提供定位漏洞所必需、且你有权分享的资料。

维护者会尽力优先处理可信安全问题,但受精力、验证条件和发布计划限制,无法承诺固定确认或修复时限;由此可能造成的不便,我们深表歉意。请在公开披露前给予合理的分析和修复时间。

English

Security fixes primarily target the latest release and main. Do not disclose unresolved vulnerability details in a public issue, discussion or pull request. Once private vulnerability reporting is available, use Security → Report a vulnerability at the link above. If it is unavailable, open a minimal issue without sensitive details and request private coordination.

Reports may be processed with AI assistance because the project relies on AI for implementation and iteration. Include only information necessary for investigation and authorized for such processing. Maintainer capacity is limited, so no fixed acknowledgement or remediation time can be guaranteed; we apologize for possible delays and ask for reasonable time before public disclosure.

There aren't any published security advisories