chore: align repository docs and ci

This commit is contained in:
xixu-me committed 2026-03-21 17:05:21 +08:00
1 parent c9a36e8e0a
commit 82c27dab5e
30 files changed
+392 -1444

No files matched your search

+42 -142
View File
@@ -1,167 +1,67 @@
name: 🐛 bug 报告
description: 报告一个问题或错误
name: Bug report
description: Report a reproducible problem in Xget
title: "[Bug]: "
labels: ["bug", "需要分类"]
assignees: []
labels:
- bug
body:
- type: markdown
attributes:
value: |
感谢你花时间填写这个 bug 报告!请尽可能详细地描述问题,这将帮助我们更快地定位和修复问题。
- type: checkboxes
id: prerequisites
attributes:
label: 前置检查
description: 在提交 Issue 之前,请确认以下事项
options:
- label: 我已经搜索过现有的 Issues,确认这不是重复问题
required: true
- label: 我已经查看过文档和 README
required: true
- label: 我已经确认当前部署配置与文档一致
required: false
Thanks for taking the time to report a bug.
Please search existing issues before filing a new one. If this is a security
vulnerability, do not continue here. Follow the private reporting instructions
in [SECURITY.md](https://github.com/xixu-me/Xget/blob/main/SECURITY.md).
- type: textarea
id: description
id: summary
attributes:
label: 问题描述
description: 清晰简洁地描述遇到的问题
placeholder: 描述你遇到了什么问题...
label: What happened?
description: Describe the problem and the actual behavior you observed.
placeholder: A request to /npm/... returns the wrong upstream path when...
validations:
required: true
- type: textarea
id: reproduction
attributes:
label: 重现步骤
description: 提供重现问题的详细步骤
placeholder: |
1. 访问 '...'
2. 执行命令 '...'
3. 观察到错误 '...'
value: |
1.
2.
3.
validations:
required: true
- type: textarea
id: expected
attributes:
label: 期望行为
description: 描述你期望发生什么
placeholder: 应该...
label: What did you expect to happen?
placeholder: The request should be rewritten to...
validations:
required: true
- type: dropdown
id: area
attributes:
label: Which area is affected?
options:
- Routing or path transformation
- Git protocol
- Docker or OCI registry support
- AI inference proxying
- Cache behavior
- Security headers or validation
- Deployment or adapter behavior
- Documentation
- Something else
validations:
required: true
- type: textarea
id: actual
id: reproduction
attributes:
label: 实际行为
description: 描述实际发生了什么
placeholder: 但实际上...
label: Steps to reproduce
description: Share a minimal reproduction with secrets removed.
placeholder: |
1. Send request to...
2. Use headers...
3. Observe...
validations:
required: true
- type: dropdown
id: platform
attributes:
label: 受影响的平台
description: 选择问题相关的平台(可多选)
multiple: true
options:
- GitHub
- GitLab
- npm
- PyPI
- Docker Hub
- crates.io
- Maven Central
- Homebrew
- Jenkins
- OpenAI API
- Anthropic API
- 其他 AI 推理 API
- 不确定/不适用
validations:
required: true
- type: dropdown
id: request_type
attributes:
label: 请求类型
description: 选择问题相关的请求类型
options:
- Git 克隆/拉取
- Git LFS
- Docker 镜像拉取
- 包下载 (npm/PyPI/Maven 等)
- AI API 推理请求
- 其他
validations:
required: true
- type: textarea
id: environment
attributes:
label: 环境信息
description: 提供你的环境详细信息
value: |
- 操作系统: [例如 Ubuntu 22.04, macOS 14, Windows 11]
- 客户端工具: [例如 git 2.40, docker 24.0, npm 10.2]
- 浏览器 (如适用): [例如 Chrome 120, Firefox 121]
- Xget 部署方式: [Cloudflare Workers / 自托管 / 其他]
validations:
required: true
- type: textarea
id: logs
attributes:
label: 错误日志
description: |
提供相关的错误日志、堆栈跟踪或控制台输出
提示: 你可以在代码块中粘贴日志以保持格式
render: shell
placeholder: |
粘贴错误日志...
- type: textarea
id: curl
attributes:
label: cURL 命令或请求示例
description: 如果可能,提供能重现问题的 cURL 命令或请求示例(请移除敏感信息)
render: shell
placeholder: |
curl -X GET "https://your-xget-instance/gh/microsoft/vscode" -H "User-Agent: git/2.40"
label: Environment
description: Include runtime, deployment target, client, and version details when relevant.
placeholder: Cloudflare Workers, local wrangler dev, curl 8.8.0, Node.js 24...
- type: textarea
id: additional
attributes:
label: 附加信息
description: |
提供任何其他有助于理解问题的上下文、截图或信息
提示: 你可以拖拽图片到这里上传
- type: dropdown
id: severity
attributes:
label: 严重程度
description: 这个问题对你的影响有多大?
options:
- 严重 - 核心功能完全无法使用
- 高 - 重要功能受阻
- 中 - 功能可用但有明显问题
- 低 - 轻微问题或不便
validations:
required: true
- type: checkboxes
id: contribution
attributes:
label: 贡献意愿
description: 你是否愿意提交 PR 来修复这个问题?
options:
- label: 我愿意提交 PR 来修复这个问题
label: Additional context
description: Logs, headers, screenshots, or links that help explain the issue.
+12 -9
View File
@@ -1,11 +1,14 @@
blank_issues_enabled: false
contact_links:
- name: 📚 文档
url: https://github.com/xixu-me/Xget/blob/main/README.zh-Hans.md
about: 查看存储库的 README 文档
- name: 🔁 URL 转换器
url: https://xuc.xi-xu.me
about: 访问配套 web 应用程序
- name: 🔐 安全漏洞报告
url: https://github.com/xixu-me/xget/security/policy#-%E6%8A%A5%E5%91%8A%E5%AE%89%E5%85%A8%E6%BC%8F%E6%B4%9E
about: 报告安全漏洞
- name: Read the README
url: https://github.com/xixu-me/Xget/blob/main/README.md
about: Check supported platforms, usage examples, and deployment options first.
- name: Contributing Guide
url: https://github.com/xixu-me/Xget/blob/main/CONTRIBUTING.md
about: Learn how to prepare a bug report or pull request.
- name: Security Policy
url: https://github.com/xixu-me/Xget/blob/main/SECURITY.md
about: Use this for private vulnerability reporting instructions.
- name: Maintainer contact page
url: https://xi-xu.me/#contact
about: Use a private contact path for sensitive or non-public matters.
-172
View File
@@ -1,172 +0,0 @@
name: 📝 文档改进
description: 报告文档问题或建议文档改进
title: "[Docs]: "
labels: ["documentation", "需要分类"]
assignees: []
body:
- type: markdown
attributes:
value: |
感谢你帮助改进文档!清晰准确的文档对存储库至关重要。
- type: dropdown
id: doc_type
attributes:
label: 文档类型
description: 这涉及哪种类型的文档?
options:
- README
- CLAUDE.md
- API 文档
- 部署指南
- 配置说明
- 使用教程
- 开发文档
- 代码注释
- 其他
validations:
required: true
- type: dropdown
id: issue_category
attributes:
label: 问题类别
description: 选择文档问题的类别
options:
- 内容缺失
- 内容过时
- 内容错误
- 不够清晰
- 示例缺失
- 示例错误
- 格式问题
- 翻译问题
- 组织结构问题
- 新内容建议
validations:
required: true
- type: textarea
id: location
attributes:
label: 文档位置
description: 指出具体的文档位置
placeholder: |
- 文件: README.md
- 章节: "部署到 Cloudflare Workers"
- 行号: 约 L123-L145
- URL: https://github.com/.../blob/main/...
validations:
required: true
- type: textarea
id: current_content
attributes:
label: 当前内容
description: 引用当前的文档内容(如果适用)
placeholder: |
当前文档中写的是:
> "..."
render: markdown
- type: textarea
id: issue_description
attributes:
label: 问题描述
description: 详细描述文档存在的问题
placeholder: |
这个文档有以下问题:
1.
2.
validations:
required: true
- type: textarea
id: suggested_content
attributes:
label: 建议的改进
description: 提供具体的改进建议或修正后的内容
placeholder: |
建议改为:
"..."
或者添加以下内容:
"..."
render: markdown
validations:
required: true
- type: textarea
id: why_important
attributes:
label: 重要性说明
description: 解释为什么这个改进很重要
placeholder: |
这个改进很重要因为:
- 现在的文档导致用户...
- 这是新用户常见的困惑点...
- 可以帮助用户更快地...
- type: textarea
id: user_perspective
attributes:
label: 用户视角
description: 从哪种用户的角度看这个文档问题?
placeholder: |
- 新用户首次部署
- 开发者集成 Xget
- 贡献者了解代码结构
- 运维人员配置环境
- type: textarea
id: examples
attributes:
label: 示例需求
description: 如果需要添加示例,请描述所需的示例类型
placeholder: |
希望添加以下示例:
- Git 克隆的完整命令示例
- Docker 拉取镜像的配置示例
- 环境变量配置的实际案例
- type: checkboxes
id: language
attributes:
label: 语言版本
description: 这个问题涉及哪些语言版本?(可多选)
options:
- label: 中文文档
- label: 英文文档
- label: 其他语言
- type: checkboxes
id: related_areas
attributes:
label: 相关领域
description: 这个文档改进可能涉及哪些领域?(可多选)
options:
- label: 快速开始指南
- label: 安装部署
- label: 配置说明
- label: 平台使用
- label: API 参考
- label: 故障排查
- label: 性能优化
- label: 安全配置
- label: 开发贡献
- label: 架构设计
- type: checkboxes
id: contribution
attributes:
label: 贡献意愿
options:
- label: 我愿意提交 PR 来改进这个文档
- label: 我可以帮助审阅文档改进
- type: textarea
id: additional
attributes:
label: 附加信息
description: 提供任何其他有助于改进文档的信息或建议
+22 -143
View File
@@ -1,167 +1,46 @@
name: ✨ 功能请求
description: 建议一个新功能或改进
name: Feature request
description: Propose an improvement or new capability for Xget
title: "[Feature]: "
labels: ["enhancement", "需要分类"]
assignees: []
labels:
- enhancement
body:
- type: markdown
attributes:
value: |
感谢你提出新功能建议!请详细描述你的想法,这将帮助我们更好地评估和实现。
- type: checkboxes
id: prerequisites
attributes:
label: 前置检查
description: 在提交功能请求之前,请确认以下事项
options:
- label: 我已经搜索过现有的 Issues 和 PR,确认这不是重复请求
required: true
- label: 我已经查看过存储库文档
required: true
- type: dropdown
id: feature_type
attributes:
label: 功能类型
description: 这个请求属于什么类型?
options:
- 新协议支持
- 性能优化
- 缓存改进
- 安全增强
- 监控/日志功能
- 配置选项
- API 改进
- 文档改进
- 开发体验改进
- 其他
validations:
required: true
Thanks for sharing an idea.
Please keep requests focused and explain the user or maintainer value clearly.
For large changes, starting with an issue before implementation is strongly preferred.
- type: textarea
id: problem
attributes:
label: 问题背景
description: 描述你想解决的问题或痛点
placeholder: |
我在使用 Xget 时遇到了...
当前的方式是...,但是...
label: What problem are you trying to solve?
description: Describe the user need, operational pain point, or workflow gap.
placeholder: Users of platform X cannot...
validations:
required: true
- type: textarea
id: solution
id: proposal
attributes:
label: 建议的解决方案
description: 清晰地描述你希望实现的功能
placeholder: 我希望 Xget 能够...
label: What change would you like to see?
description: Describe the proposed behavior or feature.
placeholder: Add support for...
validations:
required: true
- type: textarea
id: alternatives
attributes:
label: 备选方案
description: 描述你考虑过的其他替代解决方案
placeholder: |
我也考虑过...
但这个方案的问题是...
label: Alternatives considered
description: Describe any workarounds or alternative approaches you evaluated.
- type: textarea
id: use_case
attributes:
label: 使用场景
description: 描述具体的使用场景和预期效果
placeholder: |
场景 1: 当用户...时,这个功能可以...
场景 2: 在...情况下,能够...
validations:
required: true
- type: dropdown
id: priority
attributes:
label: 优先级
description: 这个功能对你有多重要?
options:
- 高 - 对我的工作流程至关重要
- 中 - 会显著改善使用体验
- 低 - 有更好,但不是必需的
validations:
required: true
- type: textarea
id: platform_specific
attributes:
label: 特定平台需求
description: 如果这是平台相关的功能请求,请提供详细信息
placeholder: |
- 平台名称:
- 平台 URL:
- API 文档:
- 认证方式:
- 特殊要求:
- type: textarea
id: technical_details
attributes:
label: 技术细节
description: 如果你有技术实现建议,请在此描述
placeholder: |
实现方式可能包括:
1. 在 platforms.js 中添加...
2. 需要处理...协议
3. 可能的挑战是...
- type: textarea
id: examples
attributes:
label: 示例和参考
description: 提供相关的示例、链接或参考实现
placeholder: |
- 类似实现:
- 官方文档:
- 示例请求:
- type: checkboxes
id: impact
attributes:
label: 影响范围
description: 这个功能可能影响哪些方面?(可多选)
options:
- label: 核心请求处理逻辑
- label: 平台配置
- label: 协议处理
- label: 缓存策略
- label: 安全性
- label: 性能
- label: 配置选项
- label: 文档
- label: 部署流程
- type: checkboxes
id: breaking
attributes:
label: 破坏性变更
description: 这个功能是否可能引入破坏性变更?
options:
- label: 可能需要破坏性变更
- label: 向后兼容
- type: checkboxes
id: contribution
attributes:
label: 贡献意愿
description: 你是否愿意参与实现这个功能?
options:
- label: 我愿意提交 PR 来实现这个功能
- label: 我可以提供测试和反馈
- label: 我可以帮助编写文档
label: Why is this valuable?
description: Explain who benefits and why the change fits Xget's goals.
validations:
required: true
- type: textarea
id: additional
attributes:
label: 附加信息
description: 提供任何其他有助于理解这个功能请求的信息
label: Additional context
description: Add links, examples, or prior art if helpful.
@@ -1,236 +0,0 @@
name: ⚡ 性能问题
description: 报告性能相关的问题或建议性能优化
title: "[Performance]: "
labels: ["performance", "需要分类"]
assignees: []
body:
- type: markdown
attributes:
value: |
感谢你报告性能问题!请提供详细的性能指标和场景,这将帮助我们诊断和优化。
- type: checkboxes
id: prerequisites
attributes:
label: 前置检查
options:
- label: 我已经搜索过现有的性能相关 Issues
required: true
- label: 我已经确认这不是上游平台本身的性能问题
required: true
- type: dropdown
id: issue_type
attributes:
label: 问题类型
description: 选择性能问题的类型
options:
- 响应时间过长
- 超时错误
- 高延迟
- 带宽限制
- 缓存未命中
- 内存使用过高
- 并发性能问题
- 其他
validations:
required: true
- type: dropdown
id: affected_platform
attributes:
label: 受影响的平台
description: 哪个平台的性能出现问题?
options:
- GitHub
- GitLab
- npm
- PyPI
- Docker Hub
- crates.io
- Maven Central
- Homebrew
- Jenkins
- OpenAI API
- Anthropic API
- 多个平台
- 所有平台
validations:
required: true
- type: dropdown
id: operation_type
attributes:
label: 操作类型
description: 什么类型的操作性能有问题?
options:
- Git 克隆
- Git 拉取
- Git LFS 下载
- Docker 镜像拉取
- 包下载
- AI API 请求
- 元数据获取
- 其他
validations:
required: true
- type: textarea
id: description
attributes:
label: 问题描述
description: 详细描述性能问题
placeholder: |
在执行...操作时,性能明显低于预期...
相比直接访问上游,速度慢了...
validations:
required: true
- type: textarea
id: metrics
attributes:
label: 性能指标
description: 提供具体的性能数据
placeholder: |
- 响应时间: XX ms (预期 < YY ms)
- 下载速度: XX KB/s (上游直连: YY KB/s)
- 首字节时间 (TTFB): XX ms
- 总耗时: XX 秒
- X-Performance-Metrics 头信息: {...}
render: markdown
validations:
required: true
- type: textarea
id: reproduction
attributes:
label: 重现步骤
description: 提供详细的重现步骤和测试命令
render: shell
placeholder: |
# 测试命令
time git clone https://your-xget-instance/gh/user/repo
# 或使用 curl 测试
curl -w "@curl-format.txt" -o /dev/null https://your-xget-instance/...
validations:
required: true
- type: textarea
id: environment
attributes:
label: 环境信息
description: 提供详细的环境信息
value: |
- Xget 部署方式: [Cloudflare Workers / 自托管 / ...]
- Xget 区域: [US/EU/ASIA/...]
- 客户端位置: [国家/地区]
- 网络环境: [家庭宽带 / 公司网络 / VPS / ...]
- ISP:
- 客户端工具版本:
- 操作系统:
validations:
required: true
- type: textarea
id: resource_size
attributes:
label: 资源规模
description: 描述涉及的资源大小
placeholder: |
- 存储库大小: XX MB
- 文件数量: XX 个
- 单个文件大小: XX MB
- Docker 镜像大小: XX GB
- 镜像层数: XX 层
- type: textarea
id: comparison
attributes:
label: 性能对比
description: 对比 Xget 与直接访问上游的性能差异
placeholder: |
| 操作 | 通过 Xget | 直接访问上游 | 差异 |
|------|-----------|--------------|------|
| 克隆 | 30s | 10s | +200% |
| 拉取 | 5s | 2s | +150% |
render: markdown
- type: textarea
id: cache_info
attributes:
label: 缓存信息
description: 检查响应的缓存相关 Header
placeholder: |
- CF-Cache-Status:
- X-Cache-Status:
- Age:
- Cache-Control:
render: markdown
- type: textarea
id: network_trace
attributes:
label: 网络追踪
description: 如果可能,提供网络追踪信息(如 curl -v 输出的关键部分)
render: shell
placeholder: |
* Connected to your-xget-instance (...)
* TLS handshake...
< HTTP/2 200
< x-performance-metrics: {...}
- type: dropdown
id: frequency
attributes:
label: 问题频率
description: 这个性能问题多久发生一次?
options:
- 每次都发生
- 经常发生 (>50%)
- 偶尔发生 (10-50%)
- 很少发生 (<10%)
validations:
required: true
- type: dropdown
id: impact
attributes:
label: 影响程度
description: 这个性能问题的影响有多大?
options:
- 严重 - 完全无法使用
- 高 - 严重影响工作效率
- 中 - 造成明显不便
- 低 - 轻微影响
validations:
required: true
- type: textarea
id: expected_performance
attributes:
label: 期望的性能
description: 描述你期望的性能指标
placeholder: |
- 理想响应时间: < 100ms
- 可接受的下载速度: > 1MB/s
- 目标改进: 减少 50% 的延迟
- type: textarea
id: suggestions
attributes:
label: 优化建议
description: 如果你有优化建议,请在此描述
placeholder: |
可能的优化方向:
- 增加缓存时长
- 使用流式传输
- 优化重试策略
- ...
- type: textarea
id: additional
attributes:
label: 附加信息
description: 提供任何其他有助于诊断性能问题的信息
-233
View File
@@ -1,233 +0,0 @@
name: 🌐 新平台支持请求
description: 请求添加对新平台的支持
title: "[Platform]: "
labels: ["platform", "enhancement", "需要分类"]
assignees: []
body:
- type: markdown
attributes:
value: |
感谢你提出新平台支持请求!请提供尽可能详细的平台信息,以便我们评估和实现。
- type: checkboxes
id: prerequisites
attributes:
label: 前置检查
options:
- label: 我已经搜索过现有的 Issues,确认这个平台还未被请求或支持
required: true
- label: 这个平台是公开可访问的服务
required: true
- type: input
id: platform_name
attributes:
label: 平台名称
description: 请提供平台的官方名称
placeholder: "例如: GitLab, Bitbucket, Quay.io"
validations:
required: true
- type: input
id: platform_url
attributes:
label: 平台 URL
description: 平台的主要域名或网址
placeholder: "例如: https://registry.example.com"
validations:
required: true
- type: dropdown
id: platform_category
attributes:
label: 平台类别
description: 这个平台属于什么类别?
options:
- 代码存储库 (Git)
- 容器注册表 (Docker/OCI)
- 软件包注册表 (npm/PyPI/Maven 等)
- AI 推理提供商
- CDN/文件存储
- 其他
validations:
required: true
- type: textarea
id: platform_description
attributes:
label: 平台描述
description: 简要描述这个平台的用途和特点
placeholder: 这个平台是一个...,主要用于...
validations:
required: true
- type: textarea
id: use_case
attributes:
label: 使用场景
description: 为什么需要加速这个平台?具体的使用场景是什么?
placeholder: |
在中国大陆访问该平台时...
我的团队经常需要从该平台下载...
加速该平台可以帮助...
validations:
required: true
- type: textarea
id: api_documentation
attributes:
label: API 文档
description: 提供平台的 API 文档链接(如果有)
placeholder: |
- 官方 API 文档:
- 认证文档:
- 其他相关文档:
- type: dropdown
id: authentication
attributes:
label: 认证方式
description: 该平台使用什么认证方式?
options:
- 无需认证(公开访问)
- API Token
- OAuth 2.0
- Basic Auth
- Bearer Token
- 自定义认证
- 不确定
validations:
required: true
- type: textarea
id: auth_details
attributes:
label: 认证详情
description: 如果需要认证,请提供详细的认证流程说明
placeholder: |
该平台的认证流程:
1.
2.
3.
- type: dropdown
id: protocol
attributes:
label: 主要协议
description: 访问该平台主要使用什么协议?
options:
- HTTP/HTTPS (RESTful API)
- Git Protocol
- Docker Registry V2
- OCI Distribution Spec
- 其他/混合
validations:
required: true
- type: textarea
id: url_structure
attributes:
label: URL 结构示例
description: 提供该平台的典型 URL 结构和示例
placeholder: |
示例 URL:
- 下载包: https://example.com/packages/{name}/{version}
- 存储库克隆: https://example.com/repos/{owner}/{repo}.git
- API 端点: https://api.example.com/v1/...
render: markdown
validations:
required: true
- type: textarea
id: special_requirements
attributes:
label: 特殊要求
description: 该平台是否有特殊的 Header、参数或处理要求?
placeholder: |
- 必需的 Headers:
- 特殊的查询参数:
- 响应格式:
- URL 重写需求:
- 其他特殊处理:
- type: textarea
id: request_examples
attributes:
label: 请求示例
description: 提供一些典型的请求示例(请移除敏感信息)
render: shell
placeholder: |
# 示例 1: 获取包信息
curl -X GET "https://example.com/api/packages/foo"
# 示例 2: 下载文件
curl -X GET "https://example.com/files/bar.tar.gz"
- type: textarea
id: response_examples
attributes:
label: 响应示例
description: 提供典型响应的示例(可以是简化版本)
render: json
placeholder: |
{
"name": "example-package",
"version": "1.0.0",
"download_url": "https://example.com/files/..."
}
- type: textarea
id: challenges
attributes:
label: 潜在挑战
description: 你认为支持这个平台可能遇到哪些挑战?
placeholder: |
- 该平台使用自定义的认证方式...
- URL 结构比较复杂...
- 需要处理特殊的重定向...
- type: textarea
id: similar_platforms
attributes:
label: 类似平台
description: 列出 Xget 已支持的类似平台(如果有)
placeholder: |
这个平台类似于已支持的:
- npm (软件包注册表)
- Docker Hub (容器注册表)
- type: input
id: estimated_users
attributes:
label: 用户基数
description: 该平台的大致用户规模或你所在团队/社区的使用情况
placeholder: "例如: 国内有约 XX 万开发者使用,我的团队有 20 人使用"
- type: dropdown
id: priority
attributes:
label: 优先级
description: 这个平台支持对你有多重要?
options:
- 高 - 我们团队急需
- 中 - 会显著改善工作流程
- 低 - 有更好,但不紧急
validations:
required: true
- type: checkboxes
id: contribution
attributes:
label: 贡献意愿
options:
- label: 我愿意提供该平台的测试账号(如果需要)
- label: 我愿意协助测试平台支持
- label: 我愿意提交 PR 来实现平台支持
- label: 我可以提供更多技术文档和细节
- type: textarea
id: additional
attributes:
label: 附加信息
description: 提供任何其他有助于实现这个平台支持的信息
+15 -98
View File
@@ -1,106 +1,23 @@
## 概述
## Summary
<!-- 请简要描述此 PR 的目的和改动内容 -->
- What does this change do?
- Why is it needed?
## 改动类型
## Testing
<!-- 请勾选适用的改动类型 -->
- [ ] 🐛 bug 修复
- [ ] ✨ 新功能
- [ ] 📝 文档更新
- [ ] 🎨 代码风格/格式调整
- [ ] ♻️ 代码重构
- [ ] ⚡️ 性能优化
- [ ] ✅ 测试相关
- [ ] 🔧 配置文件修改
- [ ] 🌐 新增平台支持
- [ ] 🔒 安全相关
## 相关 Issue
<!-- 如果此 PR 解决了某个 Issue,请在此关联 -->
Closes #
Related to #
## 改动说明
<!-- 详细描述你做了什么改动,以及为什么这样做 -->
### 主要改动
-
### 技术细节
-
## 测试
<!-- 描述你如何测试了这些改动 -->
- [ ] 已通过所有现有测试 (`npm run test:run`)
- [ ] 已添加新的测试用例
- [ ] 已在本地开发环境测试 (`npm run dev`)
- [ ] 已验证代码格式 (`npm run format:check`)
- [ ] 已通过类型检查 (`npm run type-check`)
- [ ] 已通过 lint 检查 (`npm run lint`)
### 测试环境
<!-- 描述测试的环境和场景 -->
-
## 影响范围
<!-- 此改动会影响哪些部分? -->
- [ ] 核心请求处理逻辑
- [ ] 平台配置
- [ ] 协议处理 (Git/Docker/AI)
- [ ] 缓存策略
- [ ] 安全功能
- [ ] 性能监控
- [ ] 文档
- [ ] CI/CD 流程
## 破坏性变更
<!-- 此 PR 是否包含破坏性变更?如果是,请详细说明 -->
- [ ] 是
- [ ] 否
<details>
<summary>破坏性变更详情</summary>
<!-- 如果有破坏性变更,请在此详细说明 -->
</details>
## 部署说明
<!-- 部署此改动时需要注意什么?是否需要环境变量配置? -->
-
## 截图/演示
<!-- 如果适用,请提供截图或演示 -->
- [ ] `npm run lint`
- [ ] `npm run format:check`
- [ ] `npm run test:run`
- [ ] `npm run type-check`
## Checklist
- [ ] 代码遵循存储库的编码规范
- [ ] 已进行自我代码审查
- [ ] 代码注释清晰,特别是复杂逻辑部分
- [ ] 已更新相关文档
- [ ] 改动不会产生新的警告
- [ ] 已添加必要的测试,且测试通过
- [ ] 新增和现有的单元测试都通过
- [ ] 依赖的改动已合并并发布
- [ ] I kept the change focused and avoided unrelated edits
- [ ] I added or updated tests when behavior changed
- [ ] I updated documentation when user-facing behavior changed
- [ ] I removed or redacted secrets, tokens, and private data from examples
## 附加说明
## Notes for reviewers
<!-- 其他需要审查者知道的信息 -->
- Related issue:
- Risk or rollout notes:
+57 -57
View File
@@ -1,80 +1,80 @@
# 贡献者行为准则
# Code of Conduct
## 我们的承诺
## Our commitment
作为成员、贡献者和领导者,我们承诺让每个人都能在我们的社区中获得无骚扰的体验,无论其年龄、体型、明显或不明显的残疾、种族、性别特征、性别认同和表达、经验水平、教育程度、社会经济地位、国籍、外貌、种族、宗教或性取向如何。
Xget aims to be a welcoming, respectful, and technically constructive open
source project. Contributors, maintainers, and community members are expected to
help create an environment where people can ask questions, share ideas, and
collaborate without harassment or hostility.
我们承诺以有助于建立开放、友好、多元、包容和健康社区的方式行事和互动。
## Scope
## 我们的标准
This code of conduct applies to project spaces, including:
有助于为我们社区创造积极环境的行为示例包括:
- GitHub issues, pull requests, reviews, and discussions
- Documentation, examples, and other repository content
- Community spaces or events that are explicitly presented as part of Xget
* 对他人表现出同理心和善意
* 尊重不同的观点、看法和经历
* 给予并优雅地接受建设性反馈
* 承担责任并向受我们错误影响的人道歉,并从经验中学习
* 专注于不仅对我们个人最好,而且对整个社区最好的事情
## Expected behavior
不可接受的行为示例包括:
- Be respectful and professional, even in disagreement
- Focus feedback on code, design, documentation, and behavior, not on people
- Share context, evidence, and reproduction steps when raising concerns
- Welcome contributors with different backgrounds, skill levels, and use cases
- Accept constructive feedback and course-correction gracefully
* 使用性化的语言或图像,以及任何形式的性关注或性挑逗
* 恶意评论、侮辱性或贬损性评论,以及个人或政治攻击
* 公开或私下骚扰
* 未经明确许可发布他人的私人信息,如物理地址或电子邮件地址
* 在专业环境中可能被合理认为不当的其他行为
## Unacceptable behavior
## 执行责任
- Harassment, intimidation, threats, or personal attacks
- Discriminatory or demeaning language
- Deliberate disruption, trolling, or bad-faith engagement
- Publishing private information without explicit permission
- Sexualized language or imagery in project spaces
- Repeatedly ignoring project rules, review boundaries, or moderator direction
社区领导者有责任澄清和执行我们的可接受行为标准,并将对他们认为不当、威胁、冒犯或有害的任何行为采取适当和公平的纠正措施。
## Enforcement responsibilities
社区领导者有权利和责任删除、编辑或拒绝与本行为准则不符的评论、提交、代码、wiki 编辑、问题和其他贡献,并在适当时传达审核决定的原因。
Project maintainers are responsible for clarifying and enforcing these
standards. They may take any action they consider appropriate to protect the
community, including editing or removing content, closing discussions, rejecting
contributions, temporarily restricting participation, or permanently banning a
participant from project spaces.
## 适用范围
## Reporting concerns
本行为准则适用于所有社区空间,也适用于个人在公共空间正式代表社区的情况。代表我们社区的示例包括使用官方电子邮件地址、通过官方社交媒体账户发布信息,或在线上或线下活动中担任指定代表。
If you experience or witness behavior that violates this code of conduct, report
it privately to the maintainer using the contact information published on the
maintainer contact page:
## 执行
- <https://xi-xu.me/#contact>
可以向负责执行的社区领导者报告滥用、骚扰或其他不可接受的行为,联系邮箱:<i@xi-xu.me>。
所有投诉都将得到及时和公正的审查和调查。
Please include:
所有社区领导者都有义务尊重任何事件报告者的隐私和安全。
- A description of what happened
- Links, screenshots, or other relevant evidence
- When and where the incident occurred
- Any immediate safety or privacy concerns
## 执行指南
If the report concerns the current primary maintainer, use another private
contact method listed on the same contact page, or GitHub's site-wide reporting
tools when the incident took place on GitHub.
社区领导者将遵循这些社区影响指南来确定他们认为违反本行为准则的任何行为的后果:
## Enforcement process
### 1. 纠正
- Reports will be reviewed as confidentially as practical
- Maintainers will investigate in good faith and evaluate context carefully
- Outcomes may include a warning, content removal, temporary restriction, or
permanent ban
- Retaliation against someone for making a good-faith report is itself a code of
conduct violation
**社区影响**:使用不当语言或其他被认为在社区中不专业或不受欢迎的行为。
## Project responsibility
**后果**:社区领导者的私人书面警告,澄清违规的性质并解释为什么该行为不当。可能会要求公开道歉。
Maintainers are expected to apply this policy fairly and consistently. Not every
disagreement is a code of conduct violation, but behavior that makes the project
unsafe, exclusionary, or hostile will be addressed.
### 2. 警告
## Attribution
**社区影响**:通过单一事件或一系列行为的违规。
**后果**:对持续行为后果的警告。在指定时间内不得与相关人员互动,包括与执行行为准则的人员进行主动互动。这包括避免在社区空间以及社交媒体等外部渠道中的互动。违反这些条款可能导致临时或永久禁令。
### 3. 临时禁令
**社区影响**:严重违反社区标准,包括持续的不当行为。
**后果**:在指定时间内禁止与社区进行任何形式的互动或公开交流。在此期间不允许与相关人员进行公开或私人互动,包括与执行行为准则的人员进行主动互动。违反这些条款可能导致永久禁令。
### 4. 永久禁令
**社区影响**:表现出违反社区标准的模式,包括持续的不当行为、对个人的骚扰或对某类个人的攻击或贬低。
**后果**:永久禁止在社区内进行任何形式的公开互动。
## 归属
本行为准则改编自[贡献者公约][homepage] 2.0 版,可在 <https://www.contributor-covenant.org/version/2/0/code_of_conduct.html> 获取。
社区影响指南的灵感来自 [Mozilla 的行为准则执行阶梯](https://github.com/mozilla/diversity)。
有关本行为准则常见问题的答案,请参阅 <https://www.contributor-covenant.org/faq> 的常见问题解答。翻译版本可在 <https://www.contributor-covenant.org/translations> 获取。
[homepage]: https://www.contributor-covenant.org
This document is informed by the practices recommended by Open Source Guides and
other established open source community standards.
+93 -206
View File
@@ -1,245 +1,132 @@
# 贡献指南
# Contributing to Xget
感谢您对 Xget 的关注!我们欢迎各种形式的贡献,包括但不限于代码、文档、测试、反馈和建议。
Thank you for helping improve Xget. Contributions of all sizes are welcome,
including bug reports, documentation improvements, test coverage, performance
investigations, new platform support, and code changes.
## 🤝 贡献方式
Before you contribute, please read these repository documents:
### 报告问题
- [README](README.md) for project scope, supported platforms, and deployment
options
- [Code of Conduct](CODE_OF_CONDUCT.md) for community expectations
- [Security Policy](SECURITY.md) for responsible vulnerability reporting
- [Governance](GOVERNANCE.md) for maintainer roles and decision-making
- 使用
[Issue 模板](https://github.com/xixu-me/Xget/issues/new/choose)报告 bug 或提出功能请求
- 搜索现有 issues 避免重复报告
- 提供详细的重现步骤和环境信息
## Ways to contribute
### 提交代码
- Report bugs with a minimal reproduction and clear expected behavior
- Propose features that improve correctness, usability, observability, or
maintainability
- Improve documentation, examples, or deployment guidance
- Add or expand automated tests
- Validate behavior against real clients, registries, or upstream platforms
- fork 存储库到您的 GitHub 账户
- 创建功能分支 (`git checkout -b feature/amazing-feature`)
- 安装依赖以启用本地 Git hooks (`npm install`)
- 使用 Conventional
Commits 提交更改 (`git commit -m 'feat(platforms): add amazing feature'`)
- 推送到分支 (`git push origin feature/amazing-feature`)
- 创建 Pull Request
## Before opening an issue
### 改进文档
- Search existing issues and pull requests first to avoid duplicates
- Keep one report focused on one problem or one proposal
- Include enough detail for someone else to reproduce the issue
- Do not use public issues for security vulnerabilities; follow
[SECURITY.md](SECURITY.md) instead
- 修正文档中的错误或不准确信息
- 添加使用示例和最佳实践
- 翻译文档到其他语言
- 改进代码注释和 API 文档
Useful details to include:
## 🛠️ 开发环境设置
- The request URL or request shape that failed, with secrets removed
- The upstream platform involved, such as GitHub, npm, Docker Hub, or OpenAI
- Expected behavior and actual behavior
- Steps to reproduce the problem
- Logs, screenshots, or response headers when relevant
- Your runtime or deployment environment, if it affects the issue
### 前置要求
## Development setup
- Node.js 18+
- npm 或 yarn
- Git
- Cloudflare 账户(用于测试部署)
Xget uses Node.js and Wrangler for local development.
### 本地开发
1. Install Node.js 24 and npm.
2. Install dependencies with `npm ci`.
3. Start the local worker with `npm run dev`.
4. Run tests and checks before opening a pull request.
Common commands:
```bash
# 克隆存储库
git clone https://github.com/xixu-me/Xget.git
cd Xget
# 安装依赖
npm install
# 安装后会自动启用 commit-msg hook
# 启动开发服务器
npm run dev
# 单次运行测试
npm run test:run
# 代码格式化
npm run format
# 代码检查
npm run lint
```
## 📝 代码规范
### 代码风格
- 使用 2 个空格缩进
- 使用分号结尾
- 使用单引号字符串
- 遵循 ESLint 配置规则
### 命名约定
- 变量和函数使用 camelCase
- 常量使用 UPPER_SNAKE_CASE
- 类名使用 PascalCase
- 文件名使用 kebab-case
### 注释规范
```javascript
/**
* 函数描述
* @param {string} param1 - 参数1描述
* @param {Object} param2 - 参数2描述
* @returns {Promise<Response>} 返回值描述
*/
function exampleFunction(param1, param2) {
// 实现逻辑
}
```
## 🧪 测试
### 测试类型
- **单元测试**: 测试单个函数和模块
- **集成测试**: 测试组件间的交互
- **端到端测试**: 测试完整的用户场景
### 运行测试
```bash
# 单次运行所有测试
npm run format:check
npm run test:run
# 运行特定测试文件
npm run test:run test/platforms/jenkins.test.js
# 按测试名称筛选
npm run test:run -- --testNamePattern "platform"
# 生成测试覆盖率报告
npm run test:coverage
npm run type-check
```
### 编写测试
## Repository layout
- 为新功能编写相应的测试
- 确保测试覆盖率不低于 80%
- 使用描述性的测试名称
- 测试边界情况和错误处理
- `src/` contains the Worker entry point, request pipeline, protocol handlers,
routing logic, upstream fetch helpers, and shared utilities
- `test/` contains unit, feature, platform, and integration tests
- `adapters/` contains deployment adapters for non-Workers targets
- `docs/` contains longer-form operational and deployment documentation
## 🚀 提交规范
## Pull request workflow
### Commit 消息格式
1. Fork the repository and create a branch from `main`.
2. Keep the change focused. Avoid mixing unrelated fixes.
3. Add or update tests when behavior changes.
4. Update documentation when user-facing behavior, configuration, or supported
platforms change.
5. Run the local checks listed below before requesting review.
6. Open a pull request using the repository template and explain the user impact
clearly.
使用 [Conventional Commits](https://www.conventionalcommits.org/) 规范:
```
<type>[optional scope]: <description>
[optional body]
[optional footer(s)]
```
### 类型说明
- `feat`: 新功能
- `fix`: 修复 bug
- `docs`: 文档更新
- `style`: 代码格式化(不影响功能)
- `refactor`: 代码重构
- `perf`: 性能优化
- `test`: 测试相关
- `chore`: 构建过程或辅助工具的变动
### 示例
Required local checks:
```bash
feat(platforms): add support for Bitbucket
fix(cache): resolve cache invalidation issue
docs(readme): update installation instructions
perf(proxy): optimize request handling performance
npm run lint
npm run format:check
npm run test:run
npm run type-check
```
### 自动校验
If your change affects routing, headers, cache behavior, retries, security
controls, or protocol compatibility, include test coverage for that behavior.
- `npm install` 会自动安装 `commit-msg` hook,在本地阻止不符合规范的提交
- GitHub Actions 会在 `push` 和 `pull_request`
中再次校验提交消息,防止绕过本地 hook
## Coding expectations
## 🔍 Pull Request 流程
- Follow the existing project structure and naming conventions
- Prefer small, reviewable changes over large mixed refactors
- Preserve protocol compatibility for Git, Docker, AI, and package manager
traffic
- Avoid logging secrets, tokens, or private request data
- Document new platform prefixes and examples in [README.md](README.md) when
support is added
### 提交前检查
## Commit messages
- [ ] 代码通过所有测试
- [ ] 代码符合存储库规范
- [ ] 添加了必要的测试
- [ ] 更新了相关文档
- [ ] Commit 消息符合规范
This repository uses
[Conventional Commits](https://www.conventionalcommits.org/en/v1.0.0/).
Preferred format:
### PR 描述模板
```text
type(scope): description
```
请使用 [PR 模板](.github/pull_request_template.md)填写详细信息。
Examples:
### 代码审查
- `feat(docker): normalize blob redirect handling`
- `fix(routing): preserve crates search queries`
- `docs(readme): clarify npm registry setup`
- 所有 PR 需要至少一个维护者的审查
- 解决审查中提出的问题
- 保持 PR 的焦点明确,避免混合多个不相关的更改
## Review and release expectations
## 🌟 贡献认可
- Maintainers review contributions on a best-effort basis
- Large design changes should start with an issue before implementation
- Merged changes may be edited, squashed, or followed up by maintainers to keep
the project consistent
- Acceptance of a contribution does not create an obligation for long-term
support, backports, or maintenance
### 贡献者列表
## Community standards
我们会在 README.md 中维护贡献者列表,感谢每一位贡献者的付出。
### 贡献统计
- 代码贡献会在 GitHub 贡献图中显示
- 重要贡献会在 Release Notes 中特别提及
- 长期贡献者可能被邀请成为存储库维护者
## 📋 开发任务
### 当前优先级
1. **性能优化**: 提升缓存效率和响应速度
2. **平台支持**: 添加新的代码托管和包管理平台
3. **安全增强**: 加强请求验证和安全防护
4. **监控改进**: 完善性能监控和错误追踪
### 适合新手的任务
查找标有 `good first issue` 标签的 issues,这些通常是:
- 文档改进
- 简单的 bug 修复
- 代码格式化
- 测试用例添加
## 🤔 获取帮助
### 沟通渠道
- **GitHub Issues**: 报告问题和功能请求
- **Email**: 敏感问题可发送至维护者邮箱
### 常见问题
**Q: 如何添加新平台支持?** A: 在 `src/config/platform-catalog.js`
中添加平台地址;如果需要特殊路径转换,再更新
`src/routing/platform-transformers.js`,然后补充相关文档和测试。
**Q: 如何测试 Cloudflare Workers 功能?** A: 使用 `npm run dev`
启动本地开发服务器,或部署到 Cloudflare Workers 测试环境。
**Q: 如何处理跨域问题?** A: 检查 CORS 配置,确保允许的源和方法设置正确。
## 📄 许可证
通过贡献代码,您同意您的贡献将在与存储库相同的 [AGPL-3.0 许可证](LICENSE)
下发布。
## 🙏 致谢
感谢所有为 Xget 做出贡献的开发者、测试者和用户。您的支持和反馈是存储库持续改进的动力!
---
如果您有任何问题或建议,请随时通过 GitHub Issues 与我们联系。我们期待您的参与!
By participating in this project, you agree to follow
[CODE_OF_CONDUCT.md](CODE_OF_CONDUCT.md). Please be respectful, assume good
intent, and help keep the project welcoming for users and contributors from a
wide range of backgrounds and experience levels.
+70
View File
@@ -0,0 +1,70 @@
# Governance
## Governance model
Xget currently follows a maintainer-led governance model. The project is still
small enough that a lightweight process works best, but decisions should remain
transparent and open to community input.
## Current maintainer
- [Xi Xu](https://xi-xu.com)
The primary maintainer is responsible for project direction, releases, final
review decisions, security response coordination, and enforcement of the
[Code of Conduct](CODE_OF_CONDUCT.md).
## Roles
### Users
Users rely on the project, report issues, request features, and help validate
behavior across environments.
### Contributors
Contributors improve the project through code, documentation, issue triage,
testing, design feedback, translations, operational guidance, or community
support.
### Maintainers
Maintainers are trusted contributors with additional responsibility for the
health of the project. Maintainers may review and merge changes, shape project
direction, manage releases, and coordinate responses to sensitive issues.
## Decision-making
- Day-to-day decisions are made through issues, pull requests, and maintainer
review
- Community input is encouraged for significant behavioral, API, governance, or
deployment changes
- Consensus is preferred when practical
- When consensus is unclear, the primary maintainer has final decision-making
authority
## Becoming a maintainer
Additional maintainers may be added as the project grows. The usual path is:
1. Make sustained, high-quality contributions over time
2. Demonstrate good judgment, respectful collaboration, and project context
3. Help with review, issue triage, documentation, or support beyond code alone
4. Receive an invitation from the current maintainer
There is no automatic threshold for maintainer access. Trust, consistency, and
care for the project matter more than contribution count alone.
## Project direction and releases
- The roadmap may evolve based on user needs, maintainer capacity, and platform
changes
- Maintainers may decline features that add long-term maintenance burden, reduce
security, or broaden the scope beyond the core mission of Xget
- Releases, backports, and support windows are managed on a best-effort basis
## Transparency
Important technical and product decisions should, whenever possible, be
documented in public issues, pull requests, or repository documentation so the
community can understand how the project is evolving.
+6
View File
@@ -3055,6 +3055,12 @@ We welcome all forms of contribution! Please check the
[Contributing Guide](CONTRIBUTING.md) to learn how to participate in repository
development.
Community and maintainer expectations are documented in:
- [Code of Conduct](CODE_OF_CONDUCT.md)
- [Security Policy](SECURITY.md)
- [Governance](GOVERNANCE.md)
1. **Report Issues**: Use
[issue templates](https://github.com/xixu-me/Xget/issues/new/choose) to
report bugs or propose feature requests
+6
View File
@@ -2923,6 +2923,12 @@ npx wrangler dev --log-level debug
我们欢迎各种形式的贡献!请查看[贡献指南](CONTRIBUTING.md)了解如何参与存储库开发。
社区协作与维护者职责说明请参考:
- [行为准则](CODE_OF_CONDUCT.md)
- [安全策略](SECURITY.md)
- [治理说明](GOVERNANCE.md)
1. **报告问题**: 使用
[issue 模板](https://github.com/xixu-me/Xget/issues/new/choose)报告 bug 或提出功能请求
2. **提交代码**: fork 存储库,创建功能分支,提交 pull request
+6
View File
@@ -2922,6 +2922,12 @@ npx wrangler dev --log-level debug
我們歡迎各種形式的貢獻!請檢視[貢獻指南](CONTRIBUTING.md)了解如何參與儲存庫開發。
社群協作與維護者職責說明請參考:
- [行為準則](CODE_OF_CONDUCT.md)
- [安全政策](SECURITY.md)
- [治理說明](GOVERNANCE.md)
1. **報告問題**: 使用
[issue 範本](https://github.com/xixu-me/Xget/issues/new/choose)報告 bug 或提出功能請求
2. **提交程式碼**: fork 儲存庫,建立功能分支,提交 pull request
+45 -127
View File
@@ -1,146 +1,64 @@
# 安全政策
# Security Policy
## 🚨 报告安全漏洞
Xget proxies requests across code hosting platforms, package registries,
container registries, and AI inference providers. If you believe you have found
a security vulnerability, please report it responsibly and avoid public
disclosure until maintainers have had a chance to investigate.
如果您发现了安全漏洞,请**不要**通过公开的 GitHub Issues 报告。相反,请通过以下方式私下联系我们:
## Supported versions
### 联系方式
Security fixes are developed against the latest code on `main`. Backports to
older revisions or downstream forks are not guaranteed.
- **邮箱**: <i@xi-xu.me>
- **主题**: [SECURITY] Xget 安全漏洞报告
| Version | Supported |
| ------------------------------ | ---------------- |
| `main` | Yes |
| Older commits, tags, and forks | Best effort only |
### 报告内容
## How to report a vulnerability
请在报告中包含以下信息:
Please do not open a public GitHub issue for suspected vulnerabilities.
1. **漏洞描述**: 详细描述发现的安全问题
2. **影响范围**: 说明漏洞可能造成的影响
3. **重现步骤**: 提供详细的重现步骤
4. **环境信息**: 包括平台、配置、运行环境等
5. **建议修复**: 如果有修复建议请一并提供
Instead, use one of these private channels:
### 响应时间
1. GitHub private vulnerability reporting for this repository, if it is enabled
2. The maintainer contact page at <https://xi-xu.me/#contact>
- **确认收到**: 24 小时内
- **初步评估**: 72 小时内
- **详细分析**: 7 天内
- **修复交付**: 根据严重程度,通常在 14-30 天内
Please include as much of the following as you can:
## 🛡️ 安全特性
- A clear description of the vulnerability
- The affected code path, route shape, platform prefix, or deployment flow
- Reproduction steps or a proof of concept
- Impact assessment, including confidentiality, integrity, or availability
concerns
- Any suggested remediation, if you have one
- Sanitized logs, headers, or payload samples with secrets removed
### 传输安全
## What to expect
- **强制 HTTPS**: 所有通信均通过 HTTPS 加密
- **HSTS 头**: 防止协议降级攻击
- **安全传输**: 使用现代 TLS 协议
- Maintainers will acknowledge reports on a best-effort basis
- Reports will be reviewed privately and handled confidentially where possible
- Maintainers may ask follow-up questions to validate severity and scope
- If the report is confirmed, maintainers will work toward a fix and coordinate
a disclosure timeline
### 请求安全
## Scope notes
- **方法限制**: 严格的 HTTP 方法白名单
- **路径验证**: 防止路径遍历攻击
- **长度限制**: URL 长度限制防止缓冲区溢出
- **超时保护**: 30 秒请求超时防止资源耗尽
The following are usually in scope:
### 内容安全
- Vulnerabilities in Xget source code
- Security weaknesses in official deployment manifests or adapters
- Authentication, header forwarding, request validation, cache isolation, and
secret handling issues
- **CSP 头**: 严格的内容安全策略
- **XSS 防护**: 内置跨站脚本攻击防护
- **点击劫持防护**: X-Frame-Options 头防止嵌入
- **引用策略**: 控制 HTTP 引用信息
The following are usually out of scope unless Xget directly introduces them:
### 输入验证
- Availability-only complaints caused by third-party outages
- Misconfiguration in self-hosted deployments outside the repository defaults
- Issues in upstream services that Xget only proxies
- **参数清理**: 所有输入参数严格验证
- **编码处理**: 正确的字符编码处理
- **注入防护**: 防止各类注入攻击
## Handling sensitive information
## 🔍 安全最佳实践
### 部署安全
1. **环境隔离**: 生产环境与开发环境严格分离
2. **访问控制**: 最小权限原则
3. **监控日志**: 启用详细的安全日志记录
4. **定期更新**: 及时更新依赖和运行时
### 配置安全
1. **敏感信息**: 使用环境变量存储敏感配置
2. **CORS 设置**: 合理配置跨域资源共享
3. **缓存策略**: 避免缓存敏感信息
4. **错误处理**: 不暴露内部实现细节
### 使用安全
1. **域名验证**: 确保使用可信的部署域名
2. **定期检查**: 定期检查服务状态和日志
3. **依赖更新**: 及时更新依赖和运行时环境
4. **备份恢复**: 建立完善的备份和恢复机制
## 📋 安全检查清单
### 部署前检查
- [ ] 所有依赖项已更新到安全版本
- [ ] 安全头配置正确
- [ ] 环境变量配置安全
- [ ] CORS 策略配置合理
- [ ] 日志记录已启用
### 运行时监控
- [ ] 异常请求监控
- [ ] 性能指标监控
- [ ] 错误率监控
- [ ] 资源使用监控
### 定期维护
- [ ] 依赖项安全扫描
- [ ] 代码安全审计
- [ ] 配置安全检查
- [ ] 日志分析
## 🚀 安全更新
### 更新通知
安全更新将通过以下渠道同步:
- 存储库 README
- 安全公告邮件(如适用)
### 更新优先级
- **严重**: 立即更新
- **高**: 24 小时内更新
- **中**: 7 天内更新
- **低**: 下次常规更新
## 🤝 安全贡献
### 安全研究
我们欢迎负责任的安全研究,包括:
- 代码审计
- 渗透测试
- 漏洞发现
- 安全改进建议
### 致谢
我们将在适当的地方公开感谢报告安全问题的研究人员(除非他们要求匿名)。
## 📞 紧急联系
对于严重的安全问题,请立即联系:
- **邮箱**: <i@xi-xu.me>
- **主题**: [URGENT SECURITY] 紧急安全问题
我们承诺在收到紧急安全报告后 12 小时内响应。
---
感谢您帮助保持 Xget 的安全性!
Do not include private tokens, credentials, or other secrets in public issues,
pull requests, or discussion threads. If a proof of concept requires secrets,
share them only through a private reporting channel and rotate them afterward.
+1 -1
View File
@@ -1,6 +1,6 @@
/**
* Xget - High-performance acceleration engine for developer resources
* Copyright (C) 2025 Xi Xu
* Copyright (C) Xi Xu
*
* This program is free software: you can redistribute it and/or modify
* it under the terms of the GNU Affero General Public License as published by
+1 -1
View File
@@ -1,6 +1,6 @@
/**
* Xget - High-performance acceleration engine for developer resources
* Copyright (C) 2025 Xi Xu
* Copyright (C) Xi Xu
*
* This program is free software: you can redistribute it and/or modify
* it under the terms of the GNU Affero General Public License as published by
@@ -1,6 +1,6 @@
/**
* Xget - High-performance acceleration engine for developer resources
* Copyright (C) 2025 Xi Xu
* Copyright (C) Xi Xu
*
* This program is free software: you can redistribute it and/or modify
* it under the terms of the GNU Affero General Public License as published by
@@ -20,4 +20,3 @@
* source of truth at /api/index.js.
*/
export { config, default } from '../../api/index.js';
+1 -1
View File
@@ -1,6 +1,6 @@
/**
* Xget - High-performance acceleration engine for developer resources
* Copyright (C) 2025 Xi Xu
* Copyright (C) Xi Xu
*
* This program is free software: you can redistribute it and/or modify
* it under the terms of the GNU Affero General Public License as published by
-2
View File
@@ -1,5 +1,3 @@
#!/usr/bin/env node
import { get } from 'node:https';
import { relative } from 'node:path';
import process from 'node:process';
+4 -4
View File
@@ -1,6 +1,6 @@
/**
* Xget - High-performance acceleration engine for developer resources
* Copyright (C) 2025 Xi Xu
* Copyright (C) Xi Xu
*
* This program is free software: you can redistribute it and/or modify
* it under the terms of the GNU Affero General Public License as published by
@@ -8,19 +8,19 @@
* (at your option) any later version.
*/
import { createRequestContext } from './request-context.js';
import { handleDockerAuth } from '../protocols/docker.js';
import { finalizeResponse } from '../response/finalize-response.js';
import {
createHomepageRedirect,
normalizeEffectivePath,
resolveTarget
} from '../routing/resolve-target.js';
import { finalizeResponse } from '../response/finalize-response.js';
import { handleDockerAuth } from '../protocols/docker.js';
import { getDefaultCache, tryReadCachedResponse } from '../upstream/cache.js';
import { fetchUpstreamResponse } from '../upstream/fetch-upstream.js';
import { PerformanceMonitor, addPerformanceHeaders } from '../utils/performance.js';
import { addCorsHeaders, addSecurityHeaders, createErrorResponse } from '../utils/security.js';
import { getAllowedMethods, isProtocolRequest, validateRequest } from '../utils/validation.js';
import { createRequestContext } from './request-context.js';
/**
* Main request handler with comprehensive caching, retry logic, and security measures.
+1 -1
View File
@@ -1,6 +1,6 @@
/**
* Xget - High-performance acceleration engine for developer resources
* Copyright (C) 2025 Xi Xu
* Copyright (C) Xi Xu
*
* This program is free software: you can redistribute it and/or modify
* it under the terms of the GNU Affero General Public License as published by
+1 -1
View File
@@ -1,6 +1,6 @@
/**
* Xget - High-performance acceleration engine for developer resources
* Copyright (C) 2025 Xi Xu
* Copyright (C) Xi Xu
*
* This program is free software: you can redistribute it and/or modify
* it under the terms of the GNU Affero General Public License as published by
+1 -1
View File
@@ -1,6 +1,6 @@
/**
* Xget - High-performance acceleration engine for developer resources
* Copyright (C) 2025 Xi Xu
* Copyright (C) Xi Xu
*
* This program is free software: you can redistribute it and/or modify
* it under the terms of the GNU Affero General Public License as published by
+1 -1
View File
@@ -1,6 +1,6 @@
/**
* Xget - High-performance acceleration engine for developer resources
* Copyright (C) 2025 Xi Xu
* Copyright (C) Xi Xu
*
* This program is free software: you can redistribute it and/or modify
* it under the terms of the GNU Affero General Public License as published by
+1 -1
View File
@@ -1,6 +1,6 @@
/**
* Xget - High-performance acceleration engine for developer resources
* Copyright (C) 2025 Xi Xu
* Copyright (C) Xi Xu
*
* This program is free software: you can redistribute it and/or modify
* it under the terms of the GNU Affero General Public License as published by
+1 -1
View File
@@ -1,6 +1,6 @@
/**
* Xget - High-performance acceleration engine for developer resources
* Copyright (C) 2025 Xi Xu
* Copyright (C) Xi Xu
*
* This program is free software: you can redistribute it and/or modify
* it under the terms of the GNU Affero General Public License as published by
+1 -1
View File
@@ -1,6 +1,6 @@
/**
* Xget - High-performance acceleration engine for developer resources
* Copyright (C) 2025 Xi Xu
* Copyright (C) Xi Xu
*
* This program is free software: you can redistribute it and/or modify
* it under the terms of the GNU Affero General Public License as published by
+1 -1
View File
@@ -1,6 +1,6 @@
/**
* Xget - High-performance acceleration engine for developer resources
* Copyright (C) 2025 Xi Xu
* Copyright (C) Xi Xu
*
* This program is free software: you can redistribute it and/or modify
* it under the terms of the GNU Affero General Public License as published by
+1 -1
View File
@@ -1,6 +1,6 @@
/**
* Xget - High-performance acceleration engine for developer resources
* Copyright (C) 2025 Xi Xu
* Copyright (C) Xi Xu
*
* This program is free software: you can redistribute it and/or modify
* it under the terms of the GNU Affero General Public License as published by
+1 -1
View File
@@ -1,6 +1,6 @@
/**
* Xget - High-performance acceleration engine for developer resources
* Copyright (C) 2025 Xi Xu
* Copyright (C) Xi Xu
*
* This program is free software: you can redistribute it and/or modify
* it under the terms of the GNU Affero General Public License as published by