Security-sensitiveな内容は、publicなGitHub Discussion、GitHub Issue、pull requestへ投稿しないでください。GitHub Private vulnerability reportingから非公開で報告してください。
分かる範囲で、次の情報を含めてください。すべてが揃っていなくても、private reportの送信をためらう必要はありません。
- 影響を受けるMoguet version
- environment
- 想定されるimpact
- reproduction手順またはproof
- 判明しているmitigation
Secret、実際のcredential、報告に不要な個人情報は含めないでください。
Moguetは、固定されたsecurity support window、response-time SLA、fix deadlineを保証していません。Maintainerが、報告されたversion、impact、再現情報をもとに内容をassessmentします。
通常のbugや予期しない挙動は、まずGitHub Discussionsで相談してください。具体的な再現・観測情報が十分に揃っている場合は、専用のBug Issue Formから直接報告できます。
Do not post security-sensitive details in a public GitHub Discussion, GitHub issue, or pull request. Report them privately through GitHub Private vulnerability reporting.
Include the following information where known. You can still submit a private report when some details are not yet available.
- affected Moguet version
- environment
- potential impact
- reproduction steps or proof
- known mitigation
Do not include secrets, real credentials, or personal information that is unnecessary for the report.
Moguet does not guarantee a fixed security support window, response-time SLA, or fix deadline. The maintainer will assess the affected version, impact, and reproduction information in each report.
For ordinary bugs or unexpected behavior, start with GitHub Discussions. If you have sufficient concrete reproduction and observation details, you may report the bug directly with the dedicated Bug Issue Form.