Telex has no stable release yet. Security fixes target the latest commit on the default public branch; older snapshots are not maintained.
Use the repository's private Security → Report a vulnerability flow. If private vulnerability reporting is unavailable, contact the repository owner through an existing private channel before sharing technical details.
Do not open a public issue for a suspected authentication bypass, authority escalation, credential exposure, cross-account history leak, remote crash, unsafe file access, or denial-of-service primitive.
Include:
- the affected revision;
- the exposed interface and required account or channel state;
- the smallest reproducible request or message sequence;
- the expected and observed result; and
- whether any real credential or user data may have been exposed.
Never attach a production database, app key, invitation token, password, TLS private key, transcript, or unredacted service log. Use synthetic accounts and documentation-only addresses.
This pre-alpha project does not promise a response SLA. Please allow time to reproduce and fix a report before public disclosure.