AFFiNE/SECURITY.md
DarkSky 96b3de8ce7
Some checks failed
Build & Test / Analyze (javascript, affine) (push) Has been cancelled
Build & Test / Analyze (javascript, blocksuite) (push) Has been cancelled
Build & Test / Analyze (typescript, affine) (push) Has been cancelled
Build & Test / Analyze (typescript, blocksuite) (push) Has been cancelled
Build & Test / Lint (push) Has been cancelled
Build & Test / Typecheck (push) Has been cancelled
Build & Test / Lint Rust (push) Has been cancelled
Build & Test / Check yarn binary (push) Has been cancelled
Build & Test / E2E BlockSuite Test (1) (push) Has been cancelled
Build & Test / E2E BlockSuite Test (10) (push) Has been cancelled
Build & Test / E2E BlockSuite Test (2) (push) Has been cancelled
Build & Test / E2E BlockSuite Test (3) (push) Has been cancelled
Build & Test / E2E BlockSuite Test (4) (push) Has been cancelled
Build & Test / E2E BlockSuite Test (5) (push) Has been cancelled
Build & Test / E2E BlockSuite Test (6) (push) Has been cancelled
Build & Test / E2E BlockSuite Test (7) (push) Has been cancelled
Build & Test / E2E BlockSuite Test (8) (push) Has been cancelled
Build & Test / E2E BlockSuite Test (9) (push) Has been cancelled
Build & Test / E2E BlockSuite Cross Browser Test (chromium, 1) (push) Has been cancelled
Build & Test / E2E BlockSuite Cross Browser Test (chromium, 2) (push) Has been cancelled
Build & Test / E2E BlockSuite Cross Browser Test (firefox, 1) (push) Has been cancelled
Build & Test / E2E BlockSuite Cross Browser Test (firefox, 2) (push) Has been cancelled
Build & Test / E2E BlockSuite Cross Browser Test (webkit, 1) (push) Has been cancelled
Build & Test / E2E BlockSuite Cross Browser Test (webkit, 2) (push) Has been cancelled
Build & Test / E2E Test (1) (push) Has been cancelled
Build & Test / E2E Test (10) (push) Has been cancelled
Build & Test / E2E Test (2) (push) Has been cancelled
Build & Test / E2E Test (3) (push) Has been cancelled
Build & Test / E2E Test (4) (push) Has been cancelled
Build & Test / E2E Test (5) (push) Has been cancelled
Build & Test / E2E Test (6) (push) Has been cancelled
Build & Test / E2E Test (7) (push) Has been cancelled
Build & Test / E2E Test (8) (push) Has been cancelled
Build & Test / E2E Test (9) (push) Has been cancelled
Build & Test / E2E Mobile Test (1) (push) Has been cancelled
Build & Test / E2E Mobile Test (2) (push) Has been cancelled
Build & Test / E2E Mobile Test (3) (push) Has been cancelled
Build & Test / E2E Mobile Test (4) (push) Has been cancelled
Build & Test / E2E Mobile Test (5) (push) Has been cancelled
Build & Test / Build AFFiNE native (${{ matrix.spec.target }}) (map[os:macos-latest target:aarch64-apple-darwin]) (push) Has been cancelled
Build & Test / Build AFFiNE native (${{ matrix.spec.target }}) (map[os:macos-latest target:x86_64-apple-darwin]) (push) Has been cancelled
Build & Test / Build AFFiNE native (${{ matrix.spec.target }}) (map[os:ubuntu-latest target:x86_64-unknown-linux-gnu]) (push) Has been cancelled
Build & Test / Build AFFiNE native (${{ matrix.spec.target }}) (map[os:windows-latest target:aarch64-pc-windows-msvc]) (push) Has been cancelled
Build & Test / Build AFFiNE native (${{ matrix.spec.target }}) (map[os:windows-latest target:x86_64-pc-windows-msvc]) (push) Has been cancelled
Build & Test / Build Server native (push) Has been cancelled
Build & Test / Build @affine/electron renderer (push) Has been cancelled
Build & Test / miri code check (push) Has been cancelled
Build & Test / loom thread test (push) Has been cancelled
Build & Test / fuzzing (push) Has been cancelled
Build & Test / y-octo binding test on ${{ matrix.settings.target }} (map[os:macos-13 target:x86_64-apple-darwin]) (push) Has been cancelled
Build & Test / y-octo binding test on ${{ matrix.settings.target }} (map[os:macos-latest target:aarch64-apple-darwin]) (push) Has been cancelled
Build & Test / y-octo binding test on ${{ matrix.settings.target }} (map[os:ubuntu-24.04-arm target:aarch64-unknown-linux-gnu]) (push) Has been cancelled
Build & Test / y-octo binding test on ${{ matrix.settings.target }} (map[os:ubuntu-latest target:x86_64-unknown-linux-gnu]) (push) Has been cancelled
Build & Test / y-octo binding test on ${{ matrix.settings.target }} (map[os:windows-11-arm target:aarch64-pc-windows-msvc]) (push) Has been cancelled
Build & Test / y-octo binding test on ${{ matrix.settings.target }} (map[os:windows-latest target:x86_64-pc-windows-msvc]) (push) Has been cancelled
Build & Test / Run native tests (push) Has been cancelled
Build & Test / Check Git Status (push) Has been cancelled
Build & Test / Unit Test (1) (push) Has been cancelled
Build & Test / Unit Test (2) (push) Has been cancelled
Build & Test / Unit Test (3) (push) Has been cancelled
Build & Test / Unit Test (4) (push) Has been cancelled
Build & Test / Unit Test (5) (push) Has been cancelled
Build & Test / Native Unit Test (push) Has been cancelled
Build & Test / Server Test (0, 8) (push) Has been cancelled
Build & Test / Server Test (1, 8) (push) Has been cancelled
Build & Test / Server Test (2, 8) (push) Has been cancelled
Build & Test / Server Test (3, 8) (push) Has been cancelled
Build & Test / Server Test (4, 8) (push) Has been cancelled
Build & Test / Server Test (5, 8) (push) Has been cancelled
Build & Test / Server Test (6, 8) (push) Has been cancelled
Build & Test / Server Test (7, 8) (push) Has been cancelled
Build & Test / Server Test with Elasticsearch (push) Has been cancelled
Build & Test / Server E2E Test (push) Has been cancelled
Build & Test / Server Copilot Api Test (push) Has been cancelled
Build & Test / Frontend Copilot E2E Test (1, 10) (push) Has been cancelled
Build & Test / Frontend Copilot E2E Test (10, 10) (push) Has been cancelled
Build & Test / Frontend Copilot E2E Test (2, 10) (push) Has been cancelled
Build & Test / Frontend Copilot E2E Test (3, 10) (push) Has been cancelled
Build & Test / Frontend Copilot E2E Test (4, 10) (push) Has been cancelled
Build & Test / Frontend Copilot E2E Test (5, 10) (push) Has been cancelled
Build & Test / Frontend Copilot E2E Test (6, 10) (push) Has been cancelled
Build & Test / Frontend Copilot E2E Test (7, 10) (push) Has been cancelled
Build & Test / Frontend Copilot E2E Test (8, 10) (push) Has been cancelled
Build & Test / Frontend Copilot E2E Test (9, 10) (push) Has been cancelled
Build & Test / ${{ matrix.tests.name }} (map[name:Cloud Desktop E2E Test script:yarn affine @affine/electron build:dev # Workaround for Electron apps failing to initialize on Ubuntu 24.04 due to AppArmor restrictions # Disables unprivileged user namespaces restrictio… (push) Has been cancelled
Build & Test / ${{ matrix.tests.name }} (map[name:Cloud E2E Test 1/10 script:yarn affine @affine-test/affine-cloud e2e --forbid-only --shard=1/10 shard:1]) (push) Has been cancelled
Build & Test / ${{ matrix.tests.name }} (map[name:Cloud E2E Test 10/10 script:yarn affine @affine-test/affine-cloud e2e --forbid-only --shard=10/10 shard:10]) (push) Has been cancelled
Build & Test / ${{ matrix.tests.name }} (map[name:Cloud E2E Test 2/10 script:yarn affine @affine-test/affine-cloud e2e --forbid-only --shard=2/10 shard:2]) (push) Has been cancelled
Build & Test / ${{ matrix.tests.name }} (map[name:Cloud E2E Test 3/10 script:yarn affine @affine-test/affine-cloud e2e --forbid-only --shard=3/10 shard:3]) (push) Has been cancelled
Build & Test / ${{ matrix.tests.name }} (map[name:Cloud E2E Test 4/10 script:yarn affine @affine-test/affine-cloud e2e --forbid-only --shard=4/10 shard:4]) (push) Has been cancelled
Build & Test / ${{ matrix.tests.name }} (map[name:Cloud E2E Test 5/10 script:yarn affine @affine-test/affine-cloud e2e --forbid-only --shard=5/10 shard:5]) (push) Has been cancelled
Build & Test / ${{ matrix.tests.name }} (map[name:Cloud E2E Test 6/10 script:yarn affine @affine-test/affine-cloud e2e --forbid-only --shard=6/10 shard:6]) (push) Has been cancelled
Build & Test / ${{ matrix.tests.name }} (map[name:Cloud E2E Test 7/10 script:yarn affine @affine-test/affine-cloud e2e --forbid-only --shard=7/10 shard:7]) (push) Has been cancelled
Build & Test / ${{ matrix.tests.name }} (map[name:Cloud E2E Test 8/10 script:yarn affine @affine-test/affine-cloud e2e --forbid-only --shard=8/10 shard:8]) (push) Has been cancelled
Build & Test / ${{ matrix.tests.name }} (map[name:Cloud E2E Test 9/10 script:yarn affine @affine-test/affine-cloud e2e --forbid-only --shard=9/10 shard:9]) (push) Has been cancelled
Build & Test / Desktop Test (${{ matrix.spec.os }}, ${{ matrix.spec.platform }}, ${{ matrix.spec.arch }}, ${{ matrix.spec.target }}, ${{ matrix.spec.test }}) (map[arch:arm64 os:macos-latest platform:macos target:aarch64-apple-darwin test:true]) (push) Has been cancelled
Build & Test / Desktop Test (${{ matrix.spec.os }}, ${{ matrix.spec.platform }}, ${{ matrix.spec.arch }}, ${{ matrix.spec.target }}, ${{ matrix.spec.test }}) (map[arch:x64 os:macos-latest platform:macos target:x86_64-apple-darwin test:false]) (push) Has been cancelled
Build & Test / Desktop Test (${{ matrix.spec.os }}, ${{ matrix.spec.platform }}, ${{ matrix.spec.arch }}, ${{ matrix.spec.target }}, ${{ matrix.spec.test }}) (map[arch:x64 os:ubuntu-latest platform:linux target:x86_64-unknown-linux-gnu test:true]) (push) Has been cancelled
Build & Test / Desktop Test (${{ matrix.spec.os }}, ${{ matrix.spec.platform }}, ${{ matrix.spec.arch }}, ${{ matrix.spec.target }}, ${{ matrix.spec.test }}) (map[arch:x64 os:windows-latest platform:windows target:x86_64-pc-windows-msvc test:true]) (push) Has been cancelled
Build & Test / Desktop bundle check (${{ matrix.spec.os }}, ${{ matrix.spec.platform }}, ${{ matrix.spec.arch }}, ${{ matrix.spec.target }}, ${{ matrix.spec.test }}) (map[arch:arm64 os:macos-latest platform:macos target:aarch64-apple-darwin test:true]) (push) Has been cancelled
Build & Test / Desktop bundle check (${{ matrix.spec.os }}, ${{ matrix.spec.platform }}, ${{ matrix.spec.arch }}, ${{ matrix.spec.target }}, ${{ matrix.spec.test }}) (map[arch:x64 os:macos-latest platform:macos target:x86_64-apple-darwin test:false]) (push) Has been cancelled
Build & Test / Desktop bundle check (${{ matrix.spec.os }}, ${{ matrix.spec.platform }}, ${{ matrix.spec.arch }}, ${{ matrix.spec.target }}, ${{ matrix.spec.test }}) (map[arch:x64 os:ubuntu-latest platform:linux target:x86_64-unknown-linux-gnu test:true]) (push) Has been cancelled
Build & Test / Desktop bundle check (${{ matrix.spec.os }}, ${{ matrix.spec.platform }}, ${{ matrix.spec.arch }}, ${{ matrix.spec.target }}, ${{ matrix.spec.test }}) (map[arch:x64 os:windows-latest platform:windows target:x86_64-pc-windows-msvc test:true]) (push) Has been cancelled
Build & Test / 3, 2, 1 Launch (push) Has been cancelled
chore: update docs
2025-10-04 19:29:45 +08:00

1.5 KiB

Security Policy

Supported Versions

We recommend users to always use the latest major version. Security updates will be provided for the current major version until the next major version is released.

Version Supported
0.24.x (stable)
< 0.24.x

Reporting a Vulnerability

We welcome you to provide us with bug reports via and email at security@toeverything.info or submit directly on GitHub, we encourage you to submit the relevant information directly via GitHub. We expect your report to contain at least the following for us to evaluate and reproduce:

  1. Using platform and version, for example:

    • macos arm64 0.12.0-canary-202402220729-0868ac6
    • app.affine.pro 0.12.0-canary-202402220729-0868ac6
  2. A sets of video or screenshot containing the reproduce steps that proves you successfully exploited the vulnerability, preferably including the time and software version of the successful exploit.

  3. Your classification or analysis of the vulnerability (optional)

Since we are an open source project, we also welcome you to provide corresponding fix PRs, we will determine specific rewards based on the evaluation results.

If the vulnerability is caused by a library we depend on, we encourage you to submit a security report to the corresponding dependent library at the same time to benefit more users.