Please do not report security vulnerabilities through public GitHub issues, discussions, or pull requests.
Instead, use one of the following private channels:
- Preferred — GitHub Private Vulnerability Reporting. On the affected repository, open the Security tab and click "Report a vulnerability". (Available where the repository has the feature enabled.)
- Fallback — email. If private reporting is unavailable, email shige@aikawa.jp with the details below.
Please include:
- The affected repository and version / commit
- A description of the vulnerability and its impact
- Steps to reproduce (proof of concept if possible)
- Any suggested remediation
This project is maintained on a best-effort basis by a single maintainer. There is no guaranteed response time, but reports are taken seriously and will be acknowledged as soon as reasonably possible. Please do not publicly disclose the issue until a fix is available and coordinated.
Thank you for helping keep these projects and their users safe.
セキュリティ脆弱性を、公開の GitHub Issue・Discussions・Pull Request で 報告しないでください。
以下の非公開チャネルのいずれかをご利用ください。
- 推奨 — GitHub Private Vulnerability Reporting。 対象リポジトリの Security タブを開き、「Report a vulnerability」 を クリックしてください(機能が有効なリポジトリで利用可能)。
- 代替 — メール。 非公開報告が使えない場合は、下記の情報を添えて shige@aikawa.jp までご連絡ください。
報告には以下を含めてください。
- 対象リポジトリとバージョン/コミット
- 脆弱性の内容と影響範囲
- 再現手順(可能なら PoC)
- 想定される修正案(あれば)
本プロジェクトは単独メンテナが ベストエフォートで維持しています。 応答時間の保証はありませんが、報告は真摯に受け止め、可能な限り速やかに確認します。 修正が用意され調整が済むまでは、公開での開示はお控えください。
プロジェクトと利用者の安全維持にご協力いただきありがとうございます。