# 安全政策 / Security Policy ## 报告安全问题 请不要通过公开 Issue、PR 或讨论区报告安全漏洞。优先使用 GitHub 仓库 `Security` 页面中的 **Report a vulnerability** 私密报告入口;如果该入口不可用,请通过维护者 GitHub 个人主页公开的联系方式联系,并只提供完成初步判断所需的信息。 报告应包含受影响版本、平台、复现步骤、影响范围和建议修复方向。不要上传真实账号、Cookie、访问令牌、WebDAV 凭据或漫画源配置中的敏感信息。 ## 支持范围 安全修复以 `main` 分支和最新正式版本为主。旧版本是否回补取决于问题影响范围、利用条件和维护成本。第三方漫画源及源站不在本仓库安全支持范围内。 ## Security Reports Do not report vulnerabilities through public Issues, pull requests, or discussions. Prefer **Report a vulnerability** on the repository's GitHub `Security` page. If that entry is unavailable, use the public contact on the maintainer's GitHub profile and provide only the details needed for initial triage. Include affected versions, platform, reproduction steps, impact, and a suggested direction when possible. Never include real credentials, cookies, access tokens, WebDAV credentials, or sensitive comic-source configuration. Security maintenance targets the `main` branch and the latest stable release. Backports depend on impact, exploitability, and maintenance cost. Third-party comic sources and source sites are outside this repository's security support scope.