Skip to content

Security: joeseesun/poster-studio

Security

SECURITY.md

Security Policy

Supported Version

The main branch is the actively maintained version.

Reporting a Vulnerability

请不要在公开 issue、PR、截图、日志里粘贴 API Key、Token、Cookie、七牛密钥、Remove.bg Key、Unsplash Key 或可被直接利用的漏洞细节。

Preferred reporting paths:

  • Open a private GitHub security advisory if available.
  • If private advisories are not available, contact the maintainer through X: @vista8, then share details privately.

Please include:

  • A short description of the vulnerability.
  • Affected route, file, or workflow.
  • Steps to reproduce without exposing real secrets.
  • Suggested mitigation if you have one.

We will prioritize issues that could expose secrets, bypass built-in provider guards, abuse server-owned AI generation, or write unexpected public data.

There aren't any published security advisories