Files
MyAiDesk/nomifun-tauri/SECURITY.md
T
freedak f7a720204a Update: 将子项目从 submodule 转为完整内容
- 移除 GovAI, nomifun-tauri, 算力盒子 的 submodule 引用
- 添加所有子项目的完整源代码
- 保留原始 .git 为 .git.bak 备份
2026-07-04 19:20:46 +08:00

41 lines
1.6 KiB
Markdown

# Security Policy
NomiFun can execute local tools, shell commands, browser automation, desktop
automation, and remote capability calls. Treat an authenticated NomiFun instance
as a high-privilege local automation surface.
## Reporting Vulnerabilities
Please report suspected vulnerabilities privately before opening a public issue.
If the project has not published a dedicated security contact yet, contact the
maintainers through the repository owner channel and include:
- affected version or commit,
- operating system and deployment mode (`nomifun-desktop`, `nomifun-web`, or
standalone `nomicore`),
- reproduction steps,
- impact assessment,
- logs or screenshots with secrets redacted.
Do not include live tokens, passwords, provider keys, private conversation
content, or proprietary workspace files in reports.
## Supported Versions
The project is pre-1.0. Security fixes target the current default branch unless
a release branch explicitly says it is supported.
## Deployment Guidance
- Do not expose the embedded desktop backend port directly. Use WebUI Remote
Access or `nomifun-web`, both of which provide authenticated surfaces.
- Use TLS when exposing `nomifun-web` or remote capability APIs over a network.
- Treat companion access tokens as full-control credentials for the scoped
companion and its enabled capabilities.
- Prefer least-privilege provider keys, MCP servers, and workspace paths.
- Review full-auto terminal permissions before binding them to AutoWork.
See [docs/reference/troubleshooting.md](docs/reference/troubleshooting.md) and
[docs/guides/remote-capability-api.md](docs/guides/remote-capability-api.md)
for related operational details.