# Security Policy / 安全策略

English | 简体中文

## English

`google-trends-now` is an unofficial CLI and SDK that fetches public Google Trends pages and RSS data. It does not require credentials and should not collect secrets.

Supported versions:

| Version | Supported |
|---|---|
| 0.x | Best effort |

Please report security issues **privately** through GitHub's [private vulnerability reporting](https://github.com/RuochenLyu/google-trends-now/security/advisories/new) (Security → Report a vulnerability). Do not open a public issue for a suspected vulnerability, and do not include secrets, tokens, cookies, or private network details in any public issue.

Expect an initial acknowledgement within a few days. Because this is a best-effort community project, please allow reasonable time for a fix before any public disclosure.

This project will not add code for CAPTCHA bypass, credential harvesting, login automation, proxy rotation for evasion, or other abuse-oriented behavior.

## 简体中文

`google-trends-now` 是非官方 CLI 和 SDK，用于读取公开 Google Trends 页面和 RSS 数据。它不需要凭证，也不应该收集密钥。

支持版本：

| 版本 | 支持状态 |
|---|---|
| 0.x | Best effort |

请通过 GitHub 的[私密漏洞报告](https://github.com/RuochenLyu/google-trends-now/security/advisories/new)（Security → Report a vulnerability）**私密**报告安全问题。不要为疑似漏洞创建公开 issue，也不要在任何公开 issue 中包含密钥、token、cookie 或私有网络细节。

一般会在几天内给出初步回复。由于这是尽力维护的社区项目，请在公开披露前给予合理的修复时间。

本项目不会加入验证码绕过、凭证收集、登录自动化、用于规避的代理轮换或其他滥用导向行为。
