Security fixes are applied to the current main branch.
Do not open a public issue for a suspected vulnerability.
Send a concise private report to BotsLab@proton.me with:
- affected version or commit;
- steps to reproduce;
- impact assessment;
- proof of concept, sanitized of credentials and personal data;
- a secure contact method for follow-up.
We will acknowledge the report, assess it, and coordinate a fix before public disclosure where appropriate.
Operators are responsible for protecting their own deployment: unique secrets, HTTPS, firewall restrictions, backups, agent-key rotation, and malware scanning of uploaded files. Never put credentials, production data, agent packages, database exports, attachments, or backups in a public issue or repository.