Skip to content

Security: calmmage/botspot

SECURITY.md

Security Policy

Reporting a vulnerability

Do not open a public GitHub issue, discussion, or pull request for a security-sensitive report.

Use GitHub private vulnerability reporting for this repository.

Include:

  • Affected version, tag, or commit
  • What happens and why it is security-sensitive
  • Steps to reproduce (or a proof of concept)

There is no bug bounty.

This is a Telegram bot framework. Reports about the Telegram Bot API itself belong with Telegram, not here. Strip bot tokens, API keys, and user chat contents from reproductions.

There aren't any published security advisories