Security fixes are applied to the latest version on the main branch. Pre-release builds and older commits may not receive separate fixes.
Please do not disclose a suspected vulnerability in a public issue, discussion, screenshot, or pull request.
Use GitHub's private vulnerability reporting for this repository:
- Open the repository's Security tab.
- Choose Report a vulnerability.
- Include the affected component and version, reproduction steps, expected impact, and any suggested mitigation.
If private reporting is not enabled, email zdjoey@126.com and ask for a private security channel without sharing exploit details publicly.
You should receive an acknowledgement within 7 days. We will investigate, coordinate a fix, and credit the reporter when requested and appropriate.
Never include API keys, access tokens, passwords, production URLs containing credentials, or real user learning data in a report. Redact secrets from logs and rotate any credential that may have been exposed.