中文
私密报告
请通过 GitHub 私密安全公告 报告可利用漏洞。不要在公开 issue 中发布利用代码、凭据、个人信息或未修复漏洞细节。
安全港范围
仅在你善意、最小化影响、避免访问他人数据、不进行拒绝服务且给予合理修复时间时进行测试。第三方服务、社会工程和物理攻击不在范围内。
当前措施
- 同源内容安全策略、禁止嵌入、最小权限浏览器策略。
- 有界输入、来源身份与响应模式验证、不可变证据哈希。
- 生产 D1 增量迁移、发布前备份、Worker 版本回滚和运行可观测性。
Trust · Security
报告漏洞的安全路径、当前保护措施与不应在公开问题中披露的内容。
更新 / Updated: 2026-08-18中文
请通过 GitHub 私密安全公告 报告可利用漏洞。不要在公开 issue 中发布利用代码、凭据、个人信息或未修复漏洞细节。
仅在你善意、最小化影响、避免访问他人数据、不进行拒绝服务且给予合理修复时间时进行测试。第三方服务、社会工程和物理攻击不在范围内。
English
Report exploitable vulnerabilities through a private GitHub security advisory. Do not post exploit code, credentials, personal information, or unpatched details in a public issue.
Test only in good faith, minimise impact, avoid other people's data, do not perform denial of service, and allow reasonable remediation time. Third-party services, social engineering, and physical attacks are out of scope.