Skip to content

Security: kexue-z/nonebot-plugin-htmlrender

Security

SECURITY.md

Security Policy

Supported Versions

Only actively maintained versions on the default branch are guaranteed to receive security fixes.

Reporting a Vulnerability

If you discover a security vulnerability, please do not disclose it publicly first.

Recommended process:

  1. Prepare a clear report:
    • Affected version/commit
    • Reproduction steps or PoC
    • Impact assessment
  2. Contact maintainers through private channels if available.
  3. If private channels are unavailable, open a GitHub issue with minimal details and request private follow-up.

Disclosure Policy

After confirmation and patch preparation:

  1. Maintainers coordinate a fix and release plan.
  2. Security notes are published with the release.
  3. Credits are provided when appropriate.

There aren't any published security advisories