Telegram control plane
- Configure and validate an encrypted BotFather token from System → Integrations.
- Allowlist multiple chats with independent Viewer, Operator, or Admin roles.
- View scans and validated findings; add, edit, and delete targets from Telegram.
- Start, pause, resume, cancel, and skip the current scan phase through commands and inline buttons.
Notifications and reliability
- Per-chat alerts for scan start, every completed, failed, timed-out, skipped, or cancelled phase, final scan results, monitoring changes, and validated findings.
- Finding alerts include verified native findings, verified Nuclei results, content-validated backups, verified redirects, and verified JavaScript findings.
- Durable per-chat outbox with deduplication, retry, token redaction, and restart-safe Telegram update handling.
- Bot command mutations are audit logged; target deletion always requires confirmation.
Upgrade
Existing installations migrate automatically on startup. The BotFather token is never returned after it is saved. Use a dedicated bot and grant Admin only to a private chat or a fully trusted group.
Full Changelog: v2.4.0...v2.5.0