We consider the security of our systems a top priority. But no matter how much effort we put into system security, there can still be vulnerabilities present.
If you discover a security vulnerability within our project, we would like you to inform us as soon as possible in a responsible manner. Please follow these steps for reporting:
- Send your report directly to Alibaba Security via the vulnerability reporting page: https://security.alibaba.com/. This will ensure that your report is handled in a timely and secure manner.
- Do not disclose the issue publicly until we’ve had a chance to address it. Public disclosure of a security vulnerability could put the entire community at risk.
- Provide as much information as possible about the potential vulnerability, so we can reproduce and fix the issue quickly.