# 安全政策 / Security Policy ## 支持范围 安全修复面向最新发布版本或最新候选版本。提交报告前,请先确认问题仍能在最新版本中复现。 Security fixes target the latest published release or release candidate. Before reporting an issue, please confirm that it still reproduces on the latest version. ## 私密报告漏洞 请不要通过公开 issue 披露 API Key、个人对话、工作区路径、数据库内容或可利用的漏洞细节。请使用 GitHub 的[私密漏洞报告](https://github.com/hanshanyike/dsh-yolo/security/advisories/new),并尽量提供: - 受影响版本与运行环境; - 最小复现步骤和影响范围; - 已做脱敏的日志或截图; - 可行的缓解建议(如有)。 Please do not disclose API keys, personal conversations, workspace paths, database contents, or exploitable details in a public issue. Use [GitHub private vulnerability reporting](https://github.com/hanshanyike/dsh-yolo/security/advisories/new) and include the affected version, minimal reproduction, impact, redacted evidence, and any suggested mitigation.