# 第三方研究员的安全报告

**URL:** https://meta.discourse.org/t/security-report-from-third-party-researcher/386814
**Category:** Support
**Created:** [2025年十月27日 13:14 UTC](https://meta.discourse.org/t/security-report-from-third-party-researcher/386814 "2025-10-27T13:14:06Z")
**Posts on this page:** 1
**Showing post:** 1

<div class="post-metadata">

### Author: ![raisedadead](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/raisedadead/32/240530_2.png) [@raisedadead](https://meta.discourse.org/u/raisedadead)
#### Post date: [2025年十月27日 13:14 UTC](https://meta.discourse.org/t/security-report-from-third-party-researcher/386814/1 "2025-10-27T13:14:06Z")

</div>

您好：

我们收到了来自我们 Discourse 托管实例的一名研究员的安全报告。我仔细阅读了报告，但由于我对该平台了解不足，其中一些细节对我来说并不清楚。

我阅读了安全指南，似乎我们需要通过 HackerOne 提交报告。问题是我可以选择让他们直接报告，或者自己报告（鉴于我的知识差距，可能会在翻译中丢失信息）。

在这种情况下，我是否应该直接将报告转发到您的邮箱？那样的话，我担心它可能不会被优先处理（您在指南中提到了这一点）。

抱歉提出这些问题，我只是想弄清楚下一步该怎么做。感谢您的指导，我们非常喜欢你们为我们所做的一切！

祝好。

---

_[View the full topic](https://meta.discourse.org/t/security-report-from-third-party-researcher/386814)._
