如果你认为 Reqix 存在安全漏洞,请使用本仓库的 Private vulnerability reporting 私密提交。
不要通过公开 Issue、Discussion、截图、日志或演示站点披露漏洞细节。安全报告也不要包含与漏洞验证无关的真实用户数据、凭据或第三方秘密。
报告请尽量包括:
- 受影响的 Reqix 版本、Chrome 或 Edge 版本和操作系统;
- 漏洞类型、影响范围和必要前置条件;
- 最小且安全的复现步骤或概念验证;
- 你已经观察到的实际结果;
- 建议的缓解方式(可选);
- 是否已经向任何其他人披露。
维护者会确认报告并根据影响、可复现性和修复复杂度安排处理。请在维护者完成调查和修复前保持信息私密。我们不会要求你访问不属于你的数据、降低第三方系统可用性,或开展超出验证漏洞所需范围的测试。
以下内容通常不作为安全漏洞处理:
- 仅涉及不受支持浏览器或已过期 Reqix 版本的问题;
- 未证明安全影响的界面问题;
- 需要用户主动导入并运行不可信页面脚本的行为;
- 仅说明扩展拥有已在 权限说明 中披露的浏览器权限;
- 社会工程、垃圾信息或物理攻击。
If you believe you have found a security vulnerability in Reqix, use this repository's private vulnerability reporting.
Do not disclose vulnerability details through a public Issue, Discussion, screenshot, log, or demonstration site. Do not include real user data, credentials, or third-party secrets unless they are strictly necessary to validate the issue.
Please include, where possible:
- affected Reqix, Chrome or Edge, and operating-system versions;
- vulnerability type, impact, and required preconditions;
- minimal and safe reproduction steps or proof of concept;
- the actual result you observed;
- optional mitigation ideas;
- whether the issue has been disclosed elsewhere.
Maintainers will acknowledge and prioritize reports based on impact, reproducibility, and remediation complexity. Keep the report private until investigation and remediation are complete. We will never ask you to access data you do not own, degrade a third-party service, or test beyond what is needed to validate the vulnerability.
The following are generally outside the security scope:
- problems limited to unsupported browsers or obsolete Reqix versions;
- UI defects without demonstrated security impact;
- behavior that requires a user to intentionally import and run an untrusted page script;
- statements that Reqix has browser permissions already disclosed in the Permission Explanations;
- social engineering, spam, or physical attacks.