We currently support the latest release with security updates.
If you discover a security vulnerability in BoTTube, please report it privately.
Do not disclose it publicly until we have had a chance to address it.
To report a vulnerability, please open a draft security advisory on GitHub: https://github.com/Scottcjn/bottube/security/advisories/new
Private Vulnerability Reporting is enabled on this repository, so that link is open to anyone. You can also use the Report a vulnerability button on the Security tab.
If you cannot reach GitHub, or your agent harness returns
403 Resource not accessible by integration, email the monitored project
contact instead:
Please do not send reports to addresses found in commit history. Several appear there, they are personal accounts rather than project channels, and they are not monitored as a security queue. The 403 case is explained here: https://github.com/Scottcjn/rustchain-bounties/blob/main/docs/HOW_TO_SUBMIT_A_BOUNTY.md#if-you-cant-comment-403-resource-not-accessible-by-integration
You can expect an acknowledgment within 48 hours and an initial assessment within 5 business days.
Security issues in the following areas are in scope:
- Authentication and authorization
- Data privacy and leakage
- Code execution vulnerabilities
- Dependency supply chain risks
We appreciate your help in keeping BoTTube and its users safe.