Skip to content

Security: acecore-systems/world-foundation

Security

SECURITY.md

セキュリティポリシー / Security Policy

日本語 · English

日本語

Acecore はセキュリティ上の問題を重視します。 脆弱性の報告を、公開 Issue、Pull Request、Discussion に投稿しないでください。

脆弱性の報告

リポジトリに非公開の脆弱性報告や Security Advisory の手順がある場合は、 そちらを利用してください。リポジトリ固有の手順がない場合は、公式サイトの お問い合わせフォームから Acecore に連絡してください。

https://acecore.net/contact/

報告には、問題の理解と再現に必要な情報だけを含めてください。

  • 影響を受けるリポジトリ、URL、パッケージ、機能
  • 影響範囲と想定される重大度
  • 再現手順または概念実証
  • 分かる場合は、影響を受けるバージョン、コミット、デプロイ環境
  • すでに公開されている問題かどうか

対応方針

メンテナーは、影響、悪用可能性、公開範囲をもとに報告を確認します。 修正は、コード変更、設定変更、ドキュメント更新、運用上の緩和策として行う 場合があります。

問題を示すために必要な範囲を超えて脆弱性を利用しないでください。 自分のものではないデータへアクセス、変更、公開しないでください。

English

Acecore takes security issues seriously. Do not report vulnerabilities in public Issues, pull requests, or Discussions.

Reporting a vulnerability

If the repository provides private vulnerability reporting or Security Advisory instructions, use that process. Otherwise, contact Acecore through the official contact form.

Include only the information needed to understand and reproduce the issue:

  • The affected repository, URL, package, or feature.
  • The impact and estimated severity.
  • Reproduction steps or a proof of concept.
  • Affected versions, commits, or deployment environments, if known.
  • Whether the issue has already been disclosed publicly.

Response

Maintainers will assess the impact, exploitability, and exposure. A response may involve a code or configuration change, a documentation update, or an operational mitigation.

Do not exploit a vulnerability beyond what is needed to demonstrate the issue. Do not access, change, or disclose data that does not belong to you.

There aren't any published security advisories