Please report suspected security vulnerabilities in qiankun or its packages through GitHub private vulnerability reporting. Open the repository's Security → Report a vulnerability page and submit a private report. Do not disclose vulnerability details in a public issue, discussion, or pull request.
Include the following information to help maintainers assess and reproduce the issue:
- Affected packages and exact versions, including any prerelease identifiers.
- Reproduction steps or a minimal proof of concept, with the relevant configuration and environment.
- The potential impact and any conditions required to exploit the vulnerability.
- A suggested fix or mitigation, if available.
Use the private report to discuss findings, fixes, and disclosure timing with maintainers. If Report a vulnerability is unavailable, open a public issue asking maintainers to enable private reporting or provide a private reporting channel. Do not include vulnerability details, exploit code, or sensitive data in that issue.
如果发现 qiankun 或其子包可能存在安全漏洞,请通过 GitHub 私密漏洞报告提交。在仓库中选择 Security → Report a vulnerability,填写私密报告。请勿在公开的 issue、讨论或 Pull Request 中披露漏洞细节。
为便于维护者评估和复现问题,请提供:
- 受影响的包及完整版本号,包括预发布标识。
- 复现步骤或最小验证示例,以及相关配置和运行环境。
- 漏洞可能造成的影响及利用条件。
- 修复或缓解建议(如有)。
请在私密报告中与维护者沟通调查结果、修复方案和公开披露时间。如果页面没有 Report a vulnerability 入口,可以创建公开 issue,请维护者启用私密报告或提供私密报告渠道;该 issue 中不要包含漏洞细节、利用代码或敏感数据。