If you discover a security vulnerability in FastGPT, please follow the steps below to report it:
-
How to Report You can submit a report at https://github.com/labring/FastGPT/security/advisories.
-
Response Time
- We will acknowledge receipt of your report within 48 hours.
- An initial assessment will generally be provided within 3 business days.
-
Vulnerability Handling Process
- Confirmation: We will verify the existence and scope of impact of the vulnerability.
- Fix Development: A fix will be developed for confirmed vulnerabilities.
- Release: Security patches will be released in the next version update.
- Public Disclosure: After the fix is complete, relevant information will be published in the changelog.
-
Important Notes
- Please do not publicly disclose vulnerability details before a fix has been released.
- We only accept reports about previously unknown issues, including issues covered by similar unpublished advisories or issues already identified and internally marked by the FastGPT team as risks or areas for improvement.
- Reports must concern non-test functionality; issues affecting test-only features are not eligible for acceptance.
- We welcome responsible vulnerability disclosure.
- Significant contributors will be acknowledged in the project's credits.
Thank you for contributing to the security of FastGPT!