Please do not report suspected security vulnerabilities in a public issue, discussion, or pull request.
Use the target repository's Security tab and private vulnerability reporting feature when available. If it is not available, contact the maintainers through a private channel listed in that repository. Include:
- the affected repository, component, version, or commit;
- a clear description of the vulnerability and its impact;
- reproduction steps or a proof of concept;
- known mitigations or suggested fixes, if any;
- whether the issue has been disclosed elsewhere.
Do not include credentials, personal data, or unrelated sensitive information. Please allow maintainers reasonable time to investigate and prepare a fix before public disclosure.
请勿通过公开 Issue、Discussion 或 Pull Request 报告疑似安全漏洞。优先使用目标仓库 Security 页面中的私有漏洞报告功能;如果该功能不可用,请使用仓库中列出的非公开联系方式联系维护者。
报告应包含受影响的组件和版本、影响说明、复现方法以及可能的缓解措施。请勿提交凭据或无关敏感信息,并在公开披露前为维护者预留合理的调查和修复时间。
Each RuyiAI repository defines its own supported versions and security scope. A repository-specific SECURITY.md takes precedence over this organization default.