262 Star 894 Fork 37

无闻 / gogs

加入 Gitee
与超过 1200万 开发者一起发现、参与优秀开源项目,私有仓库也完全免费 :)
免费加入
克隆/下载
SECURITY.md 1.25 KB
一键复制 编辑 原始数据 按行查看 历史

Security policy

Supported versions

Only lastest two minor version releases are supported (>= 0.12) for accepting vulnerability reports and patching fixes.

Existing vulnerability reports are being tracked in Gogs Vulnerability Reports.

Vulnerability lifecycle

  1. Report a vulnerability:
    • We strongly enourage to use https://huntr.dev/ for submitting and managing status of vulnerability reports.
    • Alternatively, you may send vulnerability reports through emails to security@gogs.io.
  2. Create a dummy issue with high-level description of the security vulnerability for credibility and tracking purposes.
  3. Project maintainers review the report and either:
    • Ask clarifying questions
    • Confirm or deny the vulnerability
  4. Once the vulnerability is confirmed, the reporter may submit a patch or wait for project maintainers to patch.
    • The latter is usually significantly slower.
  5. Patch releases will be made for the supported versions.
  6. Publish the original vulnerability report and a new GitHub security advisory.

Thank you!

Go
1
https://gitee.com/unknwon/gogs.git
git@gitee.com:unknwon/gogs.git
unknwon
gogs
gogs
main

搜索帮助