Express.js 项目在其持续致力于安全的过程中完成了一个重要里程碑:正式实现了集中化的漏洞报告和响应流程。
🌐 The Express.js project has completed a major milestone in its ongoing commitment to security: the implementation of a formal, centralized vulnerability reporting and response process.
直到最近,安全报告通常通过电子邮件处理——这种方法在初期有效,但随着 Express 日益增长的复杂性和用户群,这种方法已难以扩展。这种非正式的系统可能导致延迟、处理不一致,并增加问题被遗漏或误解的风险。
🌐 Until recently, security reports were typically handled over email — an approach that worked in the early days but no longer scaled with the growing complexity and user base of Express. This informal system introduced potential delays, inconsistent handling, and increased the risk of issues being missed or misunderstood.
感谢Sovereign Tech Fund的支持,Express.js 安全工作组现已完成对我们管理漏洞报告方式的全面重建。
🌐 Thanks to support from the Sovereign Tech Fund, the Express.js Security Working Group has now completed a ground-up overhaul of how we manage vulnerability reports.
🛠️ 主要改进
🌐 🛠️ Key Improvements
规范化漏洞报告工作流程
🌐 Formalized Vulnerability Reporting Workflow
已经创建了一份全面的操作手册和流程图,以指导维护人员完成每一步的分类、确认和处理报告的安全问题。
🌐 A comprehensive runbook and process flow have been created to guide maintainers through each step of triaging, confirming, and addressing reported security issues.
跨仓库的统一安全策略
🌐 Unified Security Policy Across Repositories
所有 Express.js 仓库现在共享一个统一的 SECURITY.md 政策,以确保一致性并消除报告者和维护者的困惑。
🌐 All Express.js repositories now share a single, unified SECURITY.md policy to ensure consistency and remove confusion for reporters and maintainers alike.
已启用 GitHub 安全公告
🌐 GitHub Security Advisories Enabled
安全公告现在已在所有 Express.js 仓库中启用,允许通过 GitHub 内置系统进行安全、私密的漏洞报告。
🌐 Security Advisories are now enabled across all Express.js repositories, allowing for secure, private vulnerability reporting through GitHub’s built-in system.
明确维护者责任
🌐 Clear Maintainer Responsibilities
关于责任归属和响应时间的期望已经明确并公布,以减少模糊性并提高响应能力。
🌐 Expectations around ownership and response timelines have been clarified and published to reduce ambiguity and improve responsiveness.
在对你的报告作出初步回复后,安全团队将努力让你了解修复和完整公告的进展情况,并可能会要求提供额外的信息或指导。
🛡️ Express 现在由 OpenJS 基金会 CNA 保护
🌐 🛡️ Express is Now Covered Under the OpenJS Foundation CNA
截至2025年6月,OpenJS基金会 正式成为 CVE编号机构 (CNA),有权为其托管项目中的安全漏洞(包括Express)分配CVE标识符。
🌐 As of June 2025, the OpenJS Foundation is officially a CVE Numbering Authority (CNA), empowered to assign CVE identifiers for security vulnerabilities across its hosted projects—including Express.
这对社区的意义是:
🌐 What this means for the community:
- Express 中的安全漏洞现在可以通过 OpenJS 获得官方 CVE 编号,从而提高透明度和协调性。
- 该基金会提供支持和工具,以简化漏洞披露流程,特别是为维护者和安全研究人员提供帮助。
- 对于关键问题,CNA 有助于确保披露遵循最佳实践,并记录在全球漏洞数据库中。
请参阅 Express 的安全政策 以了解正确的披露流程。如有需要,现在可以通过 OpenJS CNA 进行升级。
🌐 Please refer to Express’s Security Policy for the correct disclosure process. If needed, escalation routes through the OpenJS CNA are now available.
这一进展是加强 JavaScript 开源生态系统安全性更广泛努力的一部分——尤其是针对 Express 这样的广泛使用的社区驱动项目。
🌐 This advancement is part of a broader effort to strengthen the security of JavaScript’s open-source ecosystem—especially for widely used, community-driven projects like Express.
了解更多:
🌐 Learn more:
👀 即将推出:正在筹备漏洞赏金计划
🌐 👀 Coming Soon: Bug Bounty Program in the Works
为了进一步增强我们生态系统的安全性并鼓励负责任的漏洞披露,Express.js 团队已开始探索参与由Sovereign Tech Resilience 计划支持的以社区为中心的漏洞赏金计划。
🌐 To further enhance the security of our ecosystem and encourage responsible vulnerability disclosure, the Express.js team has begun exploring participation in a community-focused bug bounty initiative—powered by the Sovereign Tech Resilience program.
此次合作旨在:
🌐 This collaboration aims to:
- 奖励为发现和负责任地报告安全问题的贡献者
- 提高我们快速透明处理漏洞的能力
- 增强用户和维护者的长期韧性
加入讨论并在 expressjs/discussions#345 – 奖金漏洞提案 中分享你的想法
🌐 Join the conversation and share your thoughts in expressjs/discussions#345 – Bug Bounty Proposal
为什么这很重要
🌐 Why This Matters
安全是共同的责任——随着项目的发展,这种责任必须不断演变。通过这些更新,Express.js 为更可靠、可扩展且透明的漏洞响应系统奠定了基础。
🌐 Security is a shared responsibility — and one that must evolve as the project grows. With these updates, Express.js has laid the foundation for a more reliable, scalable, and transparent vulnerability response system.
我们感谢 OpenJS 基金会 和 Sovereign Tech Fund 的支持,并很高兴能与更广泛的社区分享这一进展。
🌐 We’re grateful to the OpenJS Foundation and the Sovereign Tech Fund for their support and are excited to share this progress with the broader community.



