Skip to content

Security: DanOps-1/Xray-VPN-OneClick

Security

SECURITY.md

Security Policy | 安全策略

Supported Versions | 支持的版本

Version Supported
1.x.x
< 1.0

Reporting a Vulnerability | 报告安全漏洞

English

If you discover a security vulnerability in this project, please report it responsibly:

  1. DO NOT create a public GitHub issue for security vulnerabilities
  2. Email the maintainer directly or use GitHub Security Advisories
  3. Include as much detail as possible:
    • Description of the vulnerability
    • Steps to reproduce
    • Potential impact
    • Suggested fix (if any)

We will respond within 48 hours and work with you to understand and resolve the issue.

中文

如果您发现本项目中的安全漏洞,请负责任地报告:

  1. 请勿 在 GitHub Issues 中公开报告安全漏洞
  2. 请直接联系维护者或使用 GitHub 安全公告
  3. 请提供尽可能详细的信息:
    • 漏洞描述
    • 复现步骤
    • 潜在影响
    • 建议的修复方案(如有)

我们将在 48 小时内 回复,并与您合作理解和解决问题。

Security Best Practices | 安全最佳实践

When using this project:

  • 🔐 Keep your server and Xray-core updated to the latest version
  • 🔑 Regularly rotate UUID and keys (every 3-6 months recommended)
  • 🛡️ Use strong SSH passwords or key-based authentication
  • 🔥 Configure firewall to only expose necessary ports (443)
  • 📊 Monitor logs for suspicious activity
  • 💾 Regularly backup your configuration

Acknowledgments | 致谢

We appreciate security researchers who help keep this project safe. Contributors who report valid security issues will be acknowledged here (with permission).

There aren’t any published security advisories