Skip to content

Security: botfusions/nanoprompt

SECURITY.md

Security Policy

Reporting a Vulnerability

We take the security of our project seriously. If you discover a security vulnerability, please report it responsibly by emailing security@botfusions.com with the following information:

  • A clear description of the vulnerability
    • Steps to reproduce the issue
      • The affected version(s)
        • Any potential impact

        • Please do not publicly disclose the vulnerability until we have addressed it.

        • Security Features

        • This repository has the following security features enabled:

          • Dependabot Alerts - Automatic detection of vulnerable dependencies
            • Dependabot Security Updates - Automatic updates for security vulnerabilities
              • CodeQL Analysis - Automated code scanning for security issues
                • Secret Scanning - Detection of exposed secrets and API keys
                  • Dependency Graph - Visibility into all project dependencies

                  • Best Practices

                  • We follow these security best practices:

                    1. Dependencies - We keep all dependencies up-to-date with security patches
                      1. Code Review - All code changes go through review before merging
                        1. Secret Management - No secrets should be committed to the repository
                          1. Branch Protection - The main branch is protected and requires reviews

                          2. Supported Versions

                          3. Please use the latest version of this project. Security updates will be released as needed.

                          4. Security Response Timeline

                            • Severe/Critical vulnerabilities: Response within 24 hours
                            • High vulnerabilities: Response within 72 hours
                            • Medium/Low vulnerabilities: Response within 7 days

                            • Thank you for helping keep our project secure!

There aren’t any published security advisories