ReceiptBI 只为最新的 1.x 版本提供安全修复。发现安全漏洞时,请勿公开提交 Issue。请使用 GitHub 的私密漏洞报告,并附上受影响版本、影响范围和复现步骤。提交前请移除凭据、个人信息和私有数据。
Security fixes are made for the latest 1.x release. The main branch may contain fixes intended for the next release. Older releases are not actively maintained.
Please do not open a public issue for a security vulnerability.
Use GitHub's private vulnerability reporting and include:
- the affected version and platform;
- a concise description of the impact;
- steps or a proof of concept that reproduce the issue;
- any suggested mitigation, if known.
Remove credentials, personal data, and private datasets from the report. The maintainer aims to acknowledge reports within seven days. Details will be kept private while the issue is assessed and a fix is prepared.
For ordinary bugs that do not have security impact, use the repository's bug report form.