- 官方站
carpool.eigentime.org; - 本仓库的代码。
自部署的站点请联系它的运营者。
请用 GitHub 的私密报告:https://github.com/wowayou/wedding-carpool/security/advisories/new。
漏洞不要公开提 issue。报告里写清楚影响、复现步骤和你用的版本,会方便很多。
- 不要在官方站上做会消耗高德额度或 Cloudflare 免费额度的测试,比如刷量、压测。需要的话,请用自己的 Key 自部署一份来测。
- 不要访问别人的行程。
这是个人业余维护的项目,收到报告后会尽快回复。
- Scope: the official site
carpool.eigentime.organd the code in this repository. For self-hosted instances, contact their operator. - Reporting: please use GitHub private vulnerability reporting: https://github.com/wowayou/wedding-carpool/security/advisories/new. Do not open a public issue for a vulnerability.
- Testing: do not run tests against the official site that consume the AMap quota or the Cloudflare free-tier quota (flooding, load tests); self-host your own copy with your own key instead. Do not access other people's trips.
- Response: this is a hobby project maintained by one person; reports are answered as soon as possible.