diff --git a/CODE_OF_CONDUCT.md b/CODE_OF_CONDUCT.md index f7fa894..bfa6311 100644 --- a/CODE_OF_CONDUCT.md +++ b/CODE_OF_CONDUCT.md @@ -1,128 +1,80 @@ -# Contributor Covenant Code of Conduct +# 贡献者行为准则 -## Our Pledge +## 我们的承诺 -We as members, contributors, and leaders pledge to make participation in our -community a harassment-free experience for everyone, regardless of age, body -size, visible or invisible disability, ethnicity, sex characteristics, gender -identity and expression, level of experience, education, socio-economic status, -nationality, personal appearance, race, religion, or sexual identity -and orientation. +作为成员、贡献者和领导者,我们承诺让每个人都能在我们的社区中获得无骚扰的体验,无论其年龄、体型、明显或不明显的残疾、种族、性别特征、性别认同和表达、经验水平、教育程度、社会经济地位、国籍、外貌、种族、宗教或性取向如何。 -We pledge to act and interact in ways that contribute to an open, welcoming, -diverse, inclusive, and healthy community. +我们承诺以有助于建立开放、友好、多元、包容和健康社区的方式行事和互动。 -## Our Standards +## 我们的标准 -Examples of behavior that contributes to a positive environment for our -community include: +有助于为我们社区创造积极环境的行为示例包括: -* Demonstrating empathy and kindness toward other people -* Being respectful of differing opinions, viewpoints, and experiences -* Giving and gracefully accepting constructive feedback -* Accepting responsibility and apologizing to those affected by our mistakes, - and learning from the experience -* Focusing on what is best not just for us as individuals, but for the - overall community +* 对他人表现出同理心和善意 +* 尊重不同的观点、看法和经历 +* 给予并优雅地接受建设性反馈 +* 承担责任并向受我们错误影响的人道歉,并从经验中学习 +* 专注于不仅对我们个人最好,而且对整个社区最好的事情 -Examples of unacceptable behavior include: +不可接受的行为示例包括: -* The use of sexualized language or imagery, and sexual attention or - advances of any kind -* Trolling, insulting or derogatory comments, and personal or political attacks -* Public or private harassment -* Publishing others' private information, such as a physical or email - address, without their explicit permission -* Other conduct which could reasonably be considered inappropriate in a - professional setting +* 使用性化的语言或图像,以及任何形式的性关注或性挑逗 +* 恶意评论、侮辱性或贬损性评论,以及个人或政治攻击 +* 公开或私下骚扰 +* 未经明确许可发布他人的私人信息,如物理地址或电子邮件地址 +* 在专业环境中可能被合理认为不当的其他行为 -## Enforcement Responsibilities +## 执行责任 -Community leaders are responsible for clarifying and enforcing our standards of -acceptable behavior and will take appropriate and fair corrective action in -response to any behavior that they deem inappropriate, threatening, offensive, -or harmful. +社区领导者有责任澄清和执行我们的可接受行为标准,并将对他们认为不当、威胁、冒犯或有害的任何行为采取适当和公平的纠正措施。 -Community leaders have the right and responsibility to remove, edit, or reject -comments, commits, code, wiki edits, issues, and other contributions that are -not aligned to this Code of Conduct, and will communicate reasons for moderation -decisions when appropriate. +社区领导者有权利和责任删除、编辑或拒绝与本行为准则不符的评论、提交、代码、wiki 编辑、问题和其他贡献,并在适当时传达审核决定的原因。 -## Scope +## 适用范围 -This Code of Conduct applies within all community spaces, and also applies when -an individual is officially representing the community in public spaces. -Examples of representing our community include using an official e-mail address, -posting via an official social media account, or acting as an appointed -representative at an online or offline event. +本行为准则适用于所有社区空间,也适用于个人在公共空间正式代表社区的情况。代表我们社区的示例包括使用官方电子邮件地址、通过官方社交媒体账户发布信息,或在线上或线下活动中担任指定代表。 -## Enforcement +## 执行 -Instances of abusive, harassing, or otherwise unacceptable behavior may be -reported to the community leaders responsible for enforcement at -. -All complaints will be reviewed and investigated promptly and fairly. +可以向负责执行的社区领导者报告滥用、骚扰或其他不可接受的行为,联系邮箱:。 +所有投诉都将得到及时和公正的审查和调查。 -All community leaders are obligated to respect the privacy and security of the -reporter of any incident. +所有社区领导者都有义务尊重任何事件报告者的隐私和安全。 -## Enforcement Guidelines +## 执行指南 -Community leaders will follow these Community Impact Guidelines in determining -the consequences for any action they deem in violation of this Code of Conduct: +社区领导者将遵循这些社区影响指南来确定他们认为违反本行为准则的任何行为的后果: -### 1. Correction +### 1. 纠正 -**Community Impact**: Use of inappropriate language or other behavior deemed -unprofessional or unwelcome in the community. +**社区影响**:使用不当语言或其他被认为在社区中不专业或不受欢迎的行为。 -**Consequence**: A private, written warning from community leaders, providing -clarity around the nature of the violation and an explanation of why the -behavior was inappropriate. A public apology may be requested. +**后果**:社区领导者的私人书面警告,澄清违规的性质并解释为什么该行为不当。可能会要求公开道歉。 -### 2. Warning +### 2. 警告 -**Community Impact**: A violation through a single incident or series -of actions. +**社区影响**:通过单一事件或一系列行为的违规。 -**Consequence**: A warning with consequences for continued behavior. No -interaction with the people involved, including unsolicited interaction with -those enforcing the Code of Conduct, for a specified period of time. This -includes avoiding interactions in community spaces as well as external channels -like social media. Violating these terms may lead to a temporary or -permanent ban. +**后果**:对持续行为后果的警告。在指定时间内不得与相关人员互动,包括与执行行为准则的人员进行主动互动。这包括避免在社区空间以及社交媒体等外部渠道中的互动。违反这些条款可能导致临时或永久禁令。 -### 3. Temporary Ban +### 3. 临时禁令 -**Community Impact**: A serious violation of community standards, including -sustained inappropriate behavior. +**社区影响**:严重违反社区标准,包括持续的不当行为。 -**Consequence**: A temporary ban from any sort of interaction or public -communication with the community for a specified period of time. No public or -private interaction with the people involved, including unsolicited interaction -with those enforcing the Code of Conduct, is allowed during this period. -Violating these terms may lead to a permanent ban. +**后果**:在指定时间内禁止与社区进行任何形式的互动或公开交流。在此期间不允许与相关人员进行公开或私人互动,包括与执行行为准则的人员进行主动互动。违反这些条款可能导致永久禁令。 -### 4. Permanent Ban +### 4. 永久禁令 -**Community Impact**: Demonstrating a pattern of violation of community -standards, including sustained inappropriate behavior, harassment of an -individual, or aggression toward or disparagement of classes of individuals. +**社区影响**:表现出违反社区标准的模式,包括持续的不当行为、对个人的骚扰或对某类个人的攻击或贬低。 -**Consequence**: A permanent ban from any sort of public interaction within -the community. +**后果**:永久禁止在社区内进行任何形式的公开互动。 -## Attribution +## 归属 -This Code of Conduct is adapted from the [Contributor Covenant][homepage], -version 2.0, available at -. +本行为准则改编自[贡献者公约][homepage] 2.0 版,可在 获取。 -Community Impact Guidelines were inspired by [Mozilla's code of conduct -enforcement ladder](https://github.com/mozilla/diversity). +社区影响指南的灵感来自 [Mozilla 的行为准则执行阶梯](https://github.com/mozilla/diversity)。 -For answers to common questions about this code of conduct, see the FAQ at -. Translations are available at -. +有关本行为准则常见问题的答案,请参阅 的常见问题解答。翻译版本可在 获取。 [homepage]: https://www.contributor-covenant.org diff --git a/SECURITY.md b/SECURITY.md index 034e848..cbe9cb0 100644 --- a/SECURITY.md +++ b/SECURITY.md @@ -1,21 +1,156 @@ -# Security Policy +# 安全政策 -## Supported Versions +## 🔒 支持的版本 -Use this section to tell people about which versions of your project are -currently being supported with security updates. +我们为以下版本提供安全更新: -| Version | Supported | -| ------- | ------------------ | -| 5.1.x | :white_check_mark: | -| 5.0.x | :x: | -| 4.0.x | :white_check_mark: | -| < 4.0 | :x: | +| 版本 | 支持状态 | +| --- | --- | +| 最新版本 | ✅ | +| 开发版本 | ⚠️ 仅限测试 | -## Reporting a Vulnerability +## 🚨 报告安全漏洞 -Use this section to tell people how to report a vulnerability. +如果您发现了安全漏洞,请**不要**通过公开的 GitHub Issues 报告。相反,请通过以下方式私下联系我们: -Tell them where to go, how often they can expect to get an update on a -reported vulnerability, what to expect if the vulnerability is accepted or -declined, etc. +### 联系方式 + +- **邮箱**: +- **主题**: [SECURITY] Xget 安全漏洞报告 + +### 报告内容 + +请在报告中包含以下信息: + +1. **漏洞描述**: 详细描述发现的安全问题 +2. **影响范围**: 说明漏洞可能造成的影响 +3. **重现步骤**: 提供详细的重现步骤 +4. **环境信息**: 包括版本、平台、配置等 +5. **建议修复**: 如果有修复建议请一并提供 + +### 响应时间 + +- **确认收到**: 24 小时内 +- **初步评估**: 72 小时内 +- **详细分析**: 7 天内 +- **修复发布**: 根据严重程度,通常在 14-30 天内 + +## 🛡️ 安全特性 + +### 传输安全 + +- **强制 HTTPS**: 所有通信均通过 HTTPS 加密 +- **HSTS 头**: 防止协议降级攻击 +- **安全传输**: 使用现代 TLS 协议 + +### 请求安全 + +- **方法限制**: 严格的 HTTP 方法白名单 +- **路径验证**: 防止路径遍历攻击 +- **长度限制**: URL 长度限制防止缓冲区溢出 +- **超时保护**: 30 秒请求超时防止资源耗尽 + +### 内容安全 + +- **CSP 头**: 严格的内容安全策略 +- **XSS 防护**: 内置跨站脚本攻击防护 +- **点击劫持防护**: X-Frame-Options 头防止嵌入 +- **引用策略**: 控制 HTTP 引用信息 + +### 输入验证 + +- **参数清理**: 所有输入参数严格验证 +- **编码处理**: 正确的字符编码处理 +- **注入防护**: 防止各类注入攻击 + +## 🔍 安全最佳实践 + +### 部署安全 + +1. **环境隔离**: 生产环境与开发环境严格分离 +2. **访问控制**: 最小权限原则 +3. **监控日志**: 启用详细的安全日志记录 +4. **定期更新**: 及时更新依赖和运行时 + +### 配置安全 + +1. **敏感信息**: 使用环境变量存储敏感配置 +2. **CORS 设置**: 合理配置跨域资源共享 +3. **缓存策略**: 避免缓存敏感信息 +4. **错误处理**: 不暴露内部实现细节 + +### 使用安全 + +1. **域名验证**: 确保使用可信的部署域名 +2. **定期检查**: 定期检查服务状态和日志 +3. **版本更新**: 及时更新到最新安全版本 +4. **备份恢复**: 建立完善的备份和恢复机制 + +## 📋 安全检查清单 + +### 部署前检查 + +- [ ] 所有依赖项已更新到最新版本 +- [ ] 安全头配置正确 +- [ ] 环境变量配置安全 +- [ ] CORS 策略配置合理 +- [ ] 日志记录已启用 + +### 运行时监控 + +- [ ] 异常请求监控 +- [ ] 性能指标监控 +- [ ] 错误率监控 +- [ ] 资源使用监控 + +### 定期维护 + +- [ ] 依赖项安全扫描 +- [ ] 代码安全审计 +- [ ] 配置安全检查 +- [ ] 日志分析 + +## 🚀 安全更新 + +### 更新通知 + +安全更新将通过以下渠道发布: + +- GitHub Releases +- 项目 README +- 安全公告邮件(如适用) + +### 更新优先级 + +- **严重**: 立即更新 +- **高**: 24 小时内更新 +- **中**: 7 天内更新 +- **低**: 下次常规更新 + +## 🤝 安全贡献 + +### 安全研究 + +我们欢迎负责任的安全研究,包括: + +- 代码审计 +- 渗透测试 +- 漏洞发现 +- 安全改进建议 + +### 致谢 + +我们将在适当的地方公开感谢报告安全问题的研究人员(除非他们要求匿名)。 + +## 📞 紧急联系 + +对于严重的安全问题,请立即联系: + +- **邮箱**: +- **主题**: [URGENT SECURITY] 紧急安全问题 + +我们承诺在收到紧急安全报告后 12 小时内响应。 + +--- + +感谢您帮助保持 Xget 的安全性!