Skip to content

Latest commit

 

History

History
54 lines (39 loc) · 2.11 KB

SECURITY.md

File metadata and controls

54 lines (39 loc) · 2.11 KB

Security Policy

Supported Versions

Version Supported
Latest
Previous ✅ (Critical fixes)
Older

We actively support the following versions of Anya-Bot: Please ensure you are using a supported version before reporting issues.

Reporting a Vulnerability

To report a security vulnerability, please follow these steps:

  1. Contact Information
    Send an email to senko_owo@gmail.com or reach out via Discord at senko_owo. Include the following details:

    • A clear and detailed description of the issue.
    • Steps to reproduce the vulnerability.
    • The potential impact of the issue.
  2. Submit via GitHub Issues
    Alternatively, open a GitHub issue. For security-sensitive issues, do not post the full details publicly. Instead, provide a brief summary and request private follow-up.

  3. Expected Response Time

    • Initial response: Within 48 hours.
    • Resolution timeline: Dependent on the severity and complexity of the issue, but typically within 14 days.

Security Issue Workflow

  • Upon receiving a vulnerability report, we will:
    1. Acknowledge the report and communicate the next steps.
    2. Investigate and reproduce the issue.
    3. Apply a patch and coordinate a release (if necessary).
    4. Credit the reporter, unless anonymity is requested.

Scope of Security Concerns

The following types of issues are considered security concerns:

  • Unauthorized access to user data.
  • Exploits allowing privilege escalation within the bot or its servers.
  • Vulnerabilities in third-party integrations used by Anya-Bot.

Exclusions

The following are not considered security vulnerabilities:

  • Bugs unrelated to security (please open a standard issue).
  • Server-specific configurations or mismanagement outside of Anya-Bot’s codebase.
  • Outdated versions no longer supported.

Thank you for contributing to the security and reliability of Anya-Bot!