Skip to content

Latest commit

 

History

History
27 lines (18 loc) · 1.5 KB

File metadata and controls

27 lines (18 loc) · 1.5 KB

Security policy

Supported version

Security fixes target the latest published release and the main branch.

Reporting a vulnerability

Please do not disclose a vulnerability in a public issue. Use the repository's private security advisory form and include reproduction steps, affected version, expected impact, and any suggested mitigation. If private advisories are unavailable, open a minimal issue asking the maintainer for a private contact channel without publishing exploit details.

Starfield Atlas processes untrusted image files and proxies astronomy tiles. Reports concerning image decoders, upload limits, path traversal, loopback API exposure, HiPS validation, cache poisoning, or executable packaging are especially useful.

安全问题报告

请勿在公开 Issue 中披露漏洞细节。优先使用仓库的私有安全公告入口,并附上复现步骤、受影响版本、潜在影响和建议缓解方式。若私有入口不可用,请只发布一条不含利用细节的简短 Issue,请维护者提供私下联系方式。

セキュリティ報告

脆弱性の詳細を公開 Issue に投稿しないでください。リポジトリの非公開 Security Advisory を利用し、再現手順、影響する版、想定される影響、緩和策を記載してください。非公開窓口が利用できない場合は、攻撃手順を含めず、管理者へ非公開連絡先を依頼してください。