Skip to content

Security: yaoxiaolinglong/zonghenghouduan

Security

SECURITY.md

安全策略

Security Policy

支持的版本 | Supported Versions

以下版本的《纵横天下》游戏后端服务目前正在接受安全更新:

The following versions of the "Zongheng Tianxia" game backend service are currently being supported with security updates:

版本 Version 支持状态 Supported
1.0.x
0.9.x
< 0.9

报告漏洞 | Reporting a Vulnerability

我们非常重视安全问题。如果您发现安全漏洞,请通过以下方式报告:

We take security issues very seriously. If you discover a security vulnerability, please report it via:

电子邮件 Email: yaoxiaolinglong@foxmail.com

请在您的报告中包含以下信息:

  • 漏洞的详细描述
  • 漏洞可能的影响
  • 复现步骤(如适用)
  • 可能的修复建议(如有)

Please include the following information in your report:

  • A detailed description of the vulnerability
  • Potential impact of the vulnerability
  • Steps to reproduce (if applicable)
  • Possible fix suggestions (if any)

响应流程 | Response Process

  1. 确认收到 - 我们会在48小时内确认收到您的报告

  2. 评估 - 我们将评估漏洞的严重性和影响

  3. 修复计划 - 我们会告知您我们计划如何以及何时修复该问题

  4. 修复发布 - 修复完成后,我们会发布更新

  5. 公开披露 - 在确保用户有足够时间更新后,我们可能会公开披露该漏洞(如适用)

  6. Acknowledgment - We will acknowledge receipt of your report within 48 hours

  7. Assessment - We will evaluate the severity and impact of the vulnerability

  8. Fix Planning - We will inform you about how and when we plan to fix the issue

  9. Fix Release - Once fixed, we will release an update

  10. Public Disclosure - After ensuring users have had adequate time to update, we may publicly disclose the vulnerability (if applicable)

注意事项 | Notes

  • 请不要公开披露潜在的安全漏洞,直到我们有机会进行修复

  • 我们不提供漏洞赏金计划,但会在修复发布后致谢您的贡献(除非您要求匿名)

  • Please do not publicly disclose potential security vulnerabilities until we have had the chance to address them

  • We do not offer a bug bounty program, but we will acknowledge your contribution in the fix release (unless you request anonymity)


感谢您帮助我们保持《纵横天下》游戏后端服务的安全!

Thank you for helping keep the "Zongheng Tianxia" game backend service secure!

There aren’t any published security advisories