We take the security of our project seriously. If you discover a security vulnerability, please report it responsibly by emailing security@botfusions.com with the following information:
- A clear description of the vulnerability
-
- Steps to reproduce the issue
-
- The affected version(s)
-
-
Any potential impact
-
Please do not publicly disclose the vulnerability until we have addressed it.
-
This repository has the following security features enabled:
-
- Dependabot Alerts - Automatic detection of vulnerable dependencies
-
- Dependabot Security Updates - Automatic updates for security vulnerabilities
-
- CodeQL Analysis - Automated code scanning for security issues
-
- Secret Scanning - Detection of exposed secrets and API keys
-
-
Dependency Graph - Visibility into all project dependencies
-
We follow these security best practices:
-
- Dependencies - We keep all dependencies up-to-date with security patches
-
- Code Review - All code changes go through review before merging
-
- Secret Management - No secrets should be committed to the repository
-
-
Branch Protection - The main branch is protected and requires reviews
-
Please use the latest version of this project. Security updates will be released as needed.
-
- Severe/Critical vulnerabilities: Response within 24 hours
- High vulnerabilities: Response within 72 hours
-
Medium/Low vulnerabilities: Response within 7 days
-
Thank you for helping keep our project secure!
-
-
-