Please report suspected vulnerabilities through GitHub's private vulnerability reporting for this repository. Do not disclose exploit details, credentials, private endpoints, user data, or proof-of-concept payloads in public Issues, Pull Requests, logs, screenshots, or test artifacts.
If private reporting is unavailable to your account, open a minimal public Issue without technical details and ask the maintainers for a private contact channel.
Use the regular Issue tracker for ordinary defects, product proposals, and crashes that do not cross a security boundary.
请通过本仓库的 GitHub private vulnerability reporting 报告疑似安全问题。不要在公开 Issue、Pull Request、日志、截图或测试产物中提交利用细节、凭据、私有 endpoint、用户数据 或 proof-of-concept payload。
如果当前账户无法使用 private reporting,请只创建一条不含技术细节的最小公开 Issue, 请求维护者提供私密联系渠道。普通功能缺陷、产品建议和不涉及安全边界的崩溃请使用常规 Issue。