Skip to content

Security: juneme/wechat-console-server

Security

SECURITY.md

安全策略

支持范围

安全修复优先应用于最新发布版本。旧版本用户应先升级并保留数据库与加密主密钥备份。

报告漏洞

请使用 GitHub 仓库的 Private vulnerability reporting / Security Advisory 私下报告。不要在公开 Issue、截图或聊天记录中提供以下内容:

  • 微信 AppSecret、access token 或 API Key;
  • 管理员密码、会话 Cookie 或真实草稿内容;
  • 可直接访问的临时图片 URL;
  • 服务器公网 IP、日志中的认证头或数据库文件。

报告中请提供受影响版本、复现步骤、实际影响和建议修复方式。维护者确认前请勿公开漏洞细节。

There aren't any published security advisories