Gridea Pro 重视用户数据与凭据安全(本地存储的部署 Token、站点内容等)。如果你发现了安全漏洞,请不要通过公开 Issue 披露,而是通过以下任一渠道私下报告:
- GitHub 私密报告(推荐):在 gridea-pro 仓库的 Security 页面 提交漏洞报告;
- 邮件:tespera@foxmail.com,标题注明
[SECURITY]。
我们会在 72 小时内确认收到,并在评估后与你沟通修复计划。修复发布后,如你愿意,我们会在发布说明中致谢。
受支持版本:仅最新 Release 版本接受安全修复,请始终保持更新。
Gridea Pro takes the security of user data and credentials seriously (locally stored deployment tokens, site content, etc.). If you discover a vulnerability, please do not open a public issue. Report it privately via either channel:
- GitHub private reporting (preferred): submit through the Security page of the gridea-pro repo;
- Email: tespera@foxmail.com with
[SECURITY]in the subject.
We will acknowledge within 72 hours and follow up with a remediation plan. With your consent, we will credit you in the release notes once a fix ships.
Supported versions: only the latest release receives security fixes — please keep your installation up to date.