JUNSHU Security treats vulnerability reports as technical collaboration. Please report suspected security issues privately and allow reasonable time for investigation before public disclosure.
The open-source ecosystem is at a foundation stage and has no production release currently declared as supported. Each future project will publish its own supported versions and security boundaries. A repository-specific policy takes precedence over this shared policy.
Do not create a public issue, discussion, pull request, or social-media post for a suspected vulnerability.
Use the affected repository's Security tab and select Report a vulnerability. If the affected repository is not public yet, or no repository-specific channel is available, submit a private security advisory in this repository.
Include, when available:
- affected repository, component, version, commit, or deployment mode;
- concise impact and realistic attack scenario;
- prerequisites, trust boundaries, and required permissions;
- reproducible steps or a minimal proof of concept;
- relevant logs with credentials and personal data removed;
- suggested mitigation or containment options;
- whether the issue has been disclosed elsewhere.
Do not send live credentials, customer data, private keys, production tokens, or unnecessary personal information. Use synthetic test data and redact sensitive values.
Maintainers will aim to:
- acknowledge receipt and establish a private channel;
- validate impact, scope, and affected versions;
- coordinate remediation and verification;
- discuss disclosure timing and credit with the reporter;
- publish an advisory when doing so helps users act safely.
No fixed response or remediation deadline is promised at this stage. Status will be communicated through the private advisory whenever possible.
Good-faith research should avoid privacy violations, service degradation, persistence, lateral movement, social engineering, and access beyond what is necessary to demonstrate impact. Stop testing and report immediately if you encounter sensitive data or affect other users.
JUNSHU Security will not recommend legal action for good-faith research that follows this policy, respects applicable law, avoids harm, and provides a reasonable opportunity to remediate. This statement does not authorize testing of third-party systems or override their policies.