Skip to content

Security: Endorpheen/IgorekChatBot

SECURITY.md

Security Policy

Supported versions

Only the latest main branch and the latest release are supported.

Report a vulnerability

Use GitHub “Report a vulnerability” (Security → Advisories) for private disclosure. Do NOT open public issues for vulnerabilities.

SLA: acknowledge within 48h, triage within 7 days, fix/mitigate within 30 days when feasible.

Scope

Included: backend (Python), web-ui (JS/TS), Docker images, CI. Excluded: third-party services and user config on self-hosted instances.

Temporary workarounds

If you have a PoC, provide minimal reproduction steps and impacted versions.


Политика безопасности (RU)

Куда писать: через “Report a vulnerability” в GitHub (приватно).
Сроки: подтверждение — 48 ч, триаж — 7 дней, фикc/митигация — до 30 дней (по возможности).
Что входит: backend (Python), web-ui (JS/TS), Docker/CI.
Не входит: сторонние сервисы и локальные настройки пользователей.
Не создавайте публичные Issue по уязвимостям.

Contacts

Primary: Telegram — @Endorpheen (https://t.me/Endorpheen) Backup: GitHub “Report a vulnerability” (Security → Advisories). PGP: not required.

There aren’t any published security advisories