Stream It! 보안 정책
Stream It! Security Policy
저희 프로젝트의 보안을 유지하고 개선하는 데 도움을 주셔서 감사합니다. 취약점 보고 및 처리 절차를 아래에 안내합니다.
Thank you for helping keep this project secure. Please review the policy below for instructions on reporting vulnerabilities.
🚨 취약점 보고 절차
보안 취약점 정보를 공개 이슈(GitHub Issues)에 올리지 말아 주세요.
패치 배포 전 취약점이 공개되면 악용될 위험이 있습니다.
1. 비밀 제보 채널
취약점 관련 상세 정보는 contact@parin.asia 이메일 또는 GitHub Private Security Advisory를 통해 제보해 주세요.
2. 포함 필수 내용
- 취약점 유형 및 영향을 받는 모듈/컴포넌트
- 재현 가능한 상세 단계 (PoC 코드, 스크린샷, 로그 등)
- 예상되는 보안 영향 및 위험 수준
3. 대응 타임라인
- 초기 확인: 제보 수신 후 48시간 이내 수신 확인 답변
- 진행 상황: 검증 및 패치 작업 진행 상황 지속 공유
메일 확인이 지연될 수 있으니, 제보 후 X(Twitter) @palin1838982 계정으로 DM을 보내 주시면 더욱 신속하게 확인하겠습니다.
🚨 Reporting a Vulnerability
Please DO NOT open a public GitHub Issue for security vulnerabilities.
Publicly disclosing a security flaw can expose users to risk before a fix is available.
1. Private Contact Channel
Please report vulnerabilities directly via email to contact@parin.asia or create a GitHub Private Security Advisory.
2. Required Information
- Type of vulnerability and affected components
- Detailed steps to reproduce (PoC code, screenshots, or logs)
- Potential impact and severity assessment
3. Response Timeline
- Initial Acknowledgement: Within 48 hours of receiving the report
- Status Updates: We will keep you updated as we investigate and develop a patch
Emails may experience delays. For urgent disclosures, please send a direct message on X (Twitter) to @palin1838982 after submitting your report.
🤝 책임 있는 공개 정책
- 비밀 유지: 보안 패치가 공식 배포될 때까지 관련 내용을 제3자에게 공개하지 않는 책임 있는 공시 관례를 준수해 주세요.
- 제보자 명시: 패치가 완료되면 원하시는 경우 릴리스 노트나 Security Advisory에 제보자 크레딧을 명시해 드립니다.
🤝 Responsible Disclosure Policy
- Confidentiality: Please adhere to responsible disclosure principles and keep details confidential until a fix has been officially released.
- Credit: Once a fix is deployed, we will gladly credit your contribution in our release notes or Security Advisory if you wish.