{"id":20669706,"url":"https://github.com/fox-one/bugs-hunter","last_synced_at":"2025-03-10T16:38:26.238Z","repository":{"id":97516172,"uuid":"219915896","full_name":"fox-one/bugs-hunter","owner":"fox-one","description":null,"archived":false,"fork":false,"pushed_at":"2020-01-10T07:37:19.000Z","size":46,"stargazers_count":6,"open_issues_count":43,"forks_count":1,"subscribers_count":10,"default_branch":"master","last_synced_at":"2025-01-17T13:32:45.345Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":null,"language":null,"has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":null,"status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/fox-one.png","metadata":{"files":{"readme":"README-zh.md","changelog":null,"contributing":null,"funding":null,"license":null,"code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null}},"created_at":"2019-11-06T05:04:09.000Z","updated_at":"2020-11-26T07:02:37.000Z","dependencies_parsed_at":"2024-03-15T16:15:52.943Z","dependency_job_id":null,"html_url":"https://github.com/fox-one/bugs-hunter","commit_stats":null,"previous_names":[],"tags_count":0,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/fox-one%2Fbugs-hunter","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/fox-one%2Fbugs-hunter/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/fox-one%2Fbugs-hunter/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/fox-one%2Fbugs-hunter/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/fox-one","download_url":"https://codeload.github.com/fox-one/bugs-hunter/tar.gz/refs/heads/master","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":242886186,"owners_count":20201503,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":[],"created_at":"2024-11-16T20:15:46.362Z","updated_at":"2025-03-10T16:38:26.232Z","avatar_url":"https://github.com/fox-one.png","language":null,"funding_links":[],"categories":[],"sub_categories":[],"readme":"[Switch to EN](https://github.com/fox-one/bugs-hunter/blob/master/README.md)\n\n# Fox.ONE 赏金猎人\n\n## 什么是赏金猎人计划\n\nFox.ONE 赏金计划为 Bug、Patch 的提交者提供 FOX 积分以及价值币 BOX 作为奖励。参与赏金计划的社区成员称之为“Fox.ONE 赏金猎人”，可以获得额外的奖励和回报。\n\n## 规则与赏金\n\n阅读以下规则，开始狩猎之旅：\n\n- 每一个 BUG 提交称为一个 Issue。\n- 提交已经被其它用户提交过的 Issue，或者是 Fox.ONE 团队确认/正在修复/修复了的 Bug，不能获取赏金\n- 直接公开严重 Bug 信息无法获得赏金\n- Fox.ONE 开发团队成员无法获得赏金\n- 计划的最终解释权归 Fox.ONE 团队所有\n\n### 赏金项目范围\n\n1. Fox.ONE 移动客户端（包括 iOS 和 Android 客户端）\n2. Fox.ONE 旗下的 Mixin 机器人，包括：\n   1. 氢定投\n   2. 闪电交易\n   3. BOX ATM\n   4. 小钱包\n\n### Bug 类型和赏金\n\nBug 根据其重要程度，依据 [OWASP](https://www.owasp.org/index.php/OWASP_Risk_Rating_Methodology) 风险模型进行定价：\n\n| 影响/出现频率 | 低概率 | 中概率 | 高概率 |\n| ------------- | ------ | ------ | ------ |\n| 较小影响      | 低   | 中     | 高     |\n| 中等影响      | 中     | 高     | 严重     |\n| 较大影响      | 高     | 严重     | 非常严重   |\n\n如上分类的奖励如下：\n\n- **非常严重**: 2000+ FC 和 1000+ BOX\n- **严重**: 200 - 2000 FC 和 100 - 1000 BOX\n- **高**: 50 - 200 FC 和 20 - 100 BOX\n- **中**: 10 - 50 FC 和 5 - 20 BOX\n- **低**: 1 - 10 FC 和 1 - 5 BOX\n\n### 提交要求\n\n提交的 BUG 需严格按照 Issue 模版的内容填写，包括并不限于：\n\n- **Bug 出现的环境**. 包括 Fox.ONE 版本、平台、机型等信息\n- **Bug 描述质量**. 表述有逻辑、清晰的 Issue 提交会获得更多的赏金。\n- **Bug 重现步骤**. 请在描述中包含能够重现问题的详细的操作步骤。\n\n### 提交方式\n\n1. 非隐私、安全类 Bug 通过官方 Issues 列表提交 https://github.com/fox-one/bugs-hunter/issues\n2. 提交的 Bug 涉及安全问题或者隐私信息，通过 Email [bug@fox.one](mailto:bug@fox.one) 提交\n\n## 免责声明\n\n赏金计划是一个社区实验性项目，它的目的是鼓励社区成员为 Fox.ONE 贡献自己的能力，不断改善 Fox.ONE，而非一个竞赛。作为一个实验项目，Fox.ONE 团队保留最终解释权和随时修改、取消项目规则的权力。最后，请参与者自行根据所在国家地区申报赏金税款，并确保参与行为遵循当地法律法规。\n\n## 常见问题\n\n### 赏金计划有期限吗？\n\n目前没有最终期限。\n\n### 怎么支付赏金？\n\n一旦 Issue 得到 Fox.ONE 团队确认，赏金会在 7 个工作日内通过 Fox.ONE 支付。为了接受赏金，你需要向我们提供你的 Referral Code（在“钱包 - 邀请朋友”中查看）\n\n### 我可以选择将我的赏金捐献给开源组织吗？\n\n可以。如果你这样做，你需要提供捐献的开源组织名称（请参阅“附表：开源组织”）。Fox.ONE 会向该组织捐赠两倍赏金，并在 Donate Leadboard 中添加你的名字、捐献的开源组织和捐赠量。\n\n备注：开源组织存在最低捐款额，或会限制捐款渠道。对此 Fox.ONE 会在达到要求前，暂时持有这一部分捐赠，直到满足捐款条件。\n\n### 我提交了 Issue，但是没收到回应\n\n开发团队非常繁忙，但是我们会尽快回复所有的提交，如果你没有收到回应，请等候五个工作日给我们发 Email。\n\n### 我希望能匿名提交\n\n如果你愿意把奖励捐赠给开源组织，那么可以匿名。否则，匿名提交 Issue 无法获得赏金。\n\n### 我有其它问题\n\n请加入 Fox.ONE 官方 Mixin 群咨询：\n\n- 中文群：7000100217\n- 英文群：7000101947\n\n## 开源组织\n\n### OpenSSL\n\n网站：https://www.openssl.org\n\nOpenSSL是用于传输层安全（TLS）和安全套接字层（SSL）协议的强大的商业级功能齐全的工具包。 它也是一个通用的密码学库。Fox.ONE 在网络协议层大量使用 OpenSSL 来保护用户的安全。\n\n### Numpy\n\n网站：http://www.numpy.org\n\nNumPy 是用Python进行科学计算的基础软件包。 Fox.ONE 使用 NumPy 实现定价模型，进行模型验证和回测。\n\n### Vue\n\n网站：https://vuejs.org\n\nVue 是一个现代化 Web 开发框架和开发套件。Fox.ONE 使用 Vue 来搭建网站和程序。\n\n### webpack\n\n网站：https://webpack.js.org\n\nWebpack 是一套用于构建 Javascript App 的套件。Fox.ONE 使用 Webpack 构建网站和程序。\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Ffox-one%2Fbugs-hunter","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Ffox-one%2Fbugs-hunter","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Ffox-one%2Fbugs-hunter/lists"}