# Security Policy

## 支持范围 / Supported versions

`dsh-memory` 目前只维护 npm 上的最新发布版本。旧版本用户应先升级到最新版本，再确认问题是否仍然存在。

`dsh-memory` currently supports only the latest version published on npm. Users of older versions should upgrade before confirming that an issue is still present.

## 报告漏洞 / Reporting a vulnerability

请不要在公开 Issue 中披露漏洞细节、用户数据、Session 内容、API key、文件路径或可直接利用的复现步骤。

仓库上线后，请优先使用 GitHub 仓库 Security 页中的私密漏洞报告入口（“Report a vulnerability”）。如果该入口尚未启用，请先通过仓库所有者的 GitHub 公开联系方式请求一个私密沟通渠道，不要公开敏感细节。

Please do not disclose vulnerability details, user data, Session contents, API keys, filesystem paths, or directly exploitable reproduction steps in a public Issue.

After the repository is published, use GitHub private vulnerability reporting through the repository's Security page (“Report a vulnerability”). If that channel is not enabled yet, contact the repository owner through their public GitHub profile to request a private channel before sharing sensitive details.

报告中可以包含受影响版本、影响范围和不包含真实凭据或私人 Session 数据的最小复现。维护者确认收到报告后，会在私密渠道中同步评估与修复进度。

A report may include the affected version, impact, and a minimal reproduction that contains no real credentials or private Session data. Once acknowledged, assessment and remediation updates will be shared through the private reporting channel.
